Cake Software Foundation CakePHP 1.3.0

CPE Details

Cake Software Foundation CakePHP 1.3.0
1.3.0
2011-01-17
18h38 +00:00
2025-01-15
16h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cakefoundation:cakephp:1.3.0:*:*:*:*:*:*:*

Informations

Vendor

cakefoundation

Product

cakephp

Version

1.3.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-15400 2020-06-30 09h42 +00:00 CakePHP before 4.0.6 mishandles CSRF token generation. This might be remotely exploitable in conjunction with XSS.
4.3
Medium
CVE-2010-4335 2011-01-14 21h00 +00:00 The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
7.5