← All CVEs

CVE-2010-4335

high · 7.5

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

7.5
CVSS
55.2%
EPSS (exploit prob.)
99th
EPSS percentile
2011-01-14
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
cakefoundationcakephp1.3.0
cakephpcakephp1.2.8
cakephpcakephp1.3
cakephpcakephp1.3.0
cakephpcakephp1.3.0
cakephpcakephp1.3.0
cakephpcakephp1.3.0
cakephpcakephp1.3.0
cakephpcakephp1.3.0
cakephpcakephp1.3.1
cakephpcakephp1.3.2
cakephpcakephp1.3.3
cakephpcakephp1.3.4
cakephpcakephp1.3.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-4335