CVE Database
/

CVE-2010-4335

Back to search

CVE-2010-4335

Published: Jan 14, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

VendorProductVersions

n/a

n/a

affected
n/a

References

16011
exploit
x_refsource_EXPLOIT-DB
69352
vdb-entry
x_refsource_OSVDB
8026
third-party-advisory
x_refsource_SREASON
42211
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now