CakePHP 1.3.4

CPE Details

CakePHP 1.3.4
1.3.4
2025-01-15
15h01 +00:00
2025-01-15
16h44 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:cakephp:cakephp:1.3.4:*:*:*:*:*:*:*

Informations

Vendor

cakephp

Product

cakephp

Version

1.3.4

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2016-4793 2017-01-23 20h00 +00:00 The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
7.5
Haute
CVE-2010-4335 2011-01-14 21h00 +00:00 The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
7.5