CVE-2012-4399
HIGHCakePHP 2.1.0-2.1.4 and 2.1.0-alpha-2.1.4 - XML External Entity Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-4399. PoCs published by Pawel Wylecial.
AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) injection vulnerability in CakePHP versions 2.x to 2.2.0-RC2. It allows an attacker to read arbitrary files from the server by crafting a malicious XML payload.
Description
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
Exploits (1)
This exploit demonstrates an XXE (XML External Entity) injection vulnerability in CakePHP versions 2.x to 2.2.0-RC2. It allows an attacker to read arbitrary files from the server by crafting a malicious XML payload.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N