Cakephp

Cakephp

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.4%
  • Veröffentlicht 26.01.2016 19:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.

Exploit
  • EPSS 1.58%
  • Veröffentlicht 23.09.2011 23:55:02
  • Zuletzt bearbeitet 16.06.2026 23:33:47

CakePHP 1.3.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by dispatcher.php and certain other files.

Exploit
  • EPSS 55.2%
  • Veröffentlicht 14.01.2011 23:00:46
  • Zuletzt bearbeitet 16.06.2026 23:24:35

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is proce...

Exploit
  • EPSS 7.34%
  • Veröffentlicht 27.09.2006 23:07:00
  • Zuletzt bearbeitet 16.06.2026 22:30:21

Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" a...

  • EPSS 1.18%
  • Veröffentlicht 10.08.2006 00:04:00
  • Zuletzt bearbeitet 16.06.2026 22:28:21

Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these d...