CakePHP 1.0.1.2708

CPE Details

CakePHP 1.0.1.2708
1.0.1.2708
2025-01-15
17h15 +00:00
2025-01-15
17h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cakephp:cakephp:1.0.1.2708:*:*:*:*:*:*:*

Informations

Vendor

cakephp

Product

cakephp

Version

1.0.1.2708

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2016-4793 2017-01-23 20h00 +00:00 The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
7.5
High
CVE-2006-5031 2006-09-27 21h00 +00:00 Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename.
5
CVE-2006-4067 2006-08-09 22h00 +00:00 Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.
4.3