CVE-2006-4067
Cakephp < 1.1.6.3264 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.
References (5)
Scores
EPSS
0.0042
EPSS Percentile
61.3%
Classification
CWE
CWE-79
Status
draft
Affected Products (6)
cakephp/cakephp
< 1.1.6.3264
cakephp/cakephp
cakephp/cakephp
cakephp/cakephp
cakephp/cakephp
cakephp/cakephp
< 1.1.7.3363Packagist
Timeline
Published
Aug 10, 2006
Tracked Since
Feb 18, 2026