V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2012-4399
DEB
HighConfirmedExploit available

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing …

CVSS
7.5
High
EPSS
0.23
p95
Published
2012-01-01
Updated
2012-01-01
Description

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Tags · CWE
Pre-auth
CWE-611
CAPEC-221
Affected products
Cakephp 2.1.0–2.1.5Cakephp 2.2.0–2.2.1
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.227 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
19863
exploitdb · https://www.exploit-db.com/exploits/19863
Enterprise
Affected software
ProductVendorStatus
cakephpTracked
cakephpTracked
cakephp*Tracked
Source databases
DEB
CVE
UBU