CakePHP 1.3.3

CPE Details

CakePHP 1.3.3
1.3.3
2021-05-20
13h53 +00:00
2025-01-15
15h01 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cakephp:cakephp:1.3.3:-:*:*:*:*:*:*

Informations

Vendor

cakephp

Product

cakephp

Version

1.3.3

Update

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-4793 2017-01-23 20h00 +00:00 The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
7.5
High
CVE-2010-4335 2011-01-14 21h00 +00:00 The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
7.5