296,147
Total vulnerabilities in the database
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
Software | From | Fixed in |
---|---|---|
cakefoundation / cakephp | 1.3.1 | 1.3.1.x |
cakefoundation / cakephp | 1.3.0 | 1.3.0.x |
cakefoundation / cakephp | 1.3.0-alpha | 1.3.0-alpha.x |
cakefoundation / cakephp | 1.2.8 | 1.2.8.x |
cakefoundation / cakephp | 1.3.0-rc2 | 1.3.0-rc2.x |
cakefoundation / cakephp | 1.3.2 | 1.3.2.x |
cakefoundation / cakephp | 1.3-dev | 1.3-dev.x |
cakefoundation / cakephp | 1.3.3 | 1.3.3.x |
cakefoundation / cakephp | 1.3.0-rc4 | 1.3.0-rc4.x |
cakefoundation / cakephp | 1.3.0-rc3 | 1.3.0-rc3.x |
cakefoundation / cakephp | 1.3.4 | 1.3.4.x |
cakefoundation / cakephp | 1.3.0-rc1 | 1.3.0-rc1.x |
cakefoundation / cakephp | 1.3.5 | 1.3.5.x |
cakefoundation / cakephp | 1.3.0-beta | 1.3.0-beta.x |
![]() |
1.2.8 | 1.3.6 |