CVE-2006-4067

Cakephp < 1.1.6.3264 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.

Scores

EPSS 0.0042
EPSS Percentile 61.3%

Classification

CWE
CWE-79
Status draft

Affected Products (6)

cakephp/cakephp < 1.1.6.3264
cakephp/cakephp
cakephp/cakephp
cakephp/cakephp
cakephp/cakephp
cakephp/cakephp < 1.1.7.3363Packagist

Timeline

Published Aug 10, 2006
Tracked Since Feb 18, 2026