Vulnerabilities > CVE-2012-4399 - XXE vulnerability in Cakefoundation Cakephp

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cakefoundation
CWE-611
exploit available

Summary

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

Exploit-Db

descriptionCakePHP 2.x-2.2.0-RC2 XXE Injection. CVE-2012-4399. Webapps exploit for php platform
fileexploits/php/webapps/19863.txt
idEDB-ID:19863
last seen2016-02-02
modified2012-07-16
platformphp
port
published2012-07-16
reporterPawel Wylecial
sourcehttps://www.exploit-db.com/download/19863/
titleCakePHP 2.x-2.2.0-RC2 XXE Injection
typewebapps