CVE-2015-8379
- EPSS 1.4%
- Veröffentlicht 26.01.2016 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.
- EPSS 1.58%
- Veröffentlicht 23.09.2011 23:55:02
- Zuletzt bearbeitet 16.06.2026 23:33:47
CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.
CVE-2010-4335
- EPSS 55.2%
- Veröffentlicht 14.01.2011 23:00:46
- Zuletzt bearbeitet 16.06.2026 23:24:35
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is proce...
- EPSS 7.34%
- Veröffentlicht 27.09.2006 23:07:00
- Zuletzt bearbeitet 16.06.2026 22:30:21
Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" a...
CVE-2006-4067
- EPSS 1.18%
- Veröffentlicht 10.08.2006 00:04:00
- Zuletzt bearbeitet 16.06.2026 22:28:21
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these d...