Логотип exploitDog
bind:CVE-2010-4335
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2010-4335

Количество 4

Количество 4

ubuntu логотип

CVE-2010-4335

почти 15 лет назад

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

CVSS2: 7.5
EPSS: Высокий
nvd логотип

CVE-2010-4335

почти 15 лет назад

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

CVSS2: 7.5
EPSS: Высокий
debian логотип

CVE-2010-4335

почти 15 лет назад

The _validatePost function in libs/controller/components/security.php ...

CVSS2: 7.5
EPSS: Высокий
github логотип

GHSA-g2vx-8v47-4vhh

больше 3 лет назад

CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-4335

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

CVSS2: 7.5
83%
Высокий
почти 15 лет назад
nvd логотип
CVE-2010-4335

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

CVSS2: 7.5
83%
Высокий
почти 15 лет назад
debian логотип
CVE-2010-4335

The _validatePost function in libs/controller/components/security.php ...

CVSS2: 7.5
83%
Высокий
почти 15 лет назад
github логотип
GHSA-g2vx-8v47-4vhh

CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code

83%
Высокий
больше 3 лет назад

Уязвимостей на страницу