Vulnerability Description
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cakefoundation | Cakephp | >= 2.1.0, < 2.1.5 |
Related Weaknesses (CWE)
References
- http://bakery.cakephp.org/articles/markstory/2012/07/14/security_release_-_cakepBroken LinkVendor Advisory
- http://seclists.org/bugtraq/2012/Jul/101ExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/49900Broken LinkVendor Advisory
- http://www.exploit-db.com/exploits/19863ExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2012/09/03/1Mailing List
- http://www.openwall.com/lists/oss-security/2012/09/03/2Mailing List
- http://www.osvdb.org/84042Broken Link
- http://bakery.cakephp.org/articles/markstory/2012/07/14/security_release_-_cakepBroken LinkVendor Advisory
- http://seclists.org/bugtraq/2012/Jul/101ExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/49900Broken LinkVendor Advisory
- http://www.exploit-db.com/exploits/19863ExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2012/09/03/1Mailing List
- http://www.openwall.com/lists/oss-security/2012/09/03/2Mailing List
- http://www.osvdb.org/84042Broken Link
FAQ
What is CVE-2012-4399?
CVE-2012-4399 is a vulnerability with a CVSS score of 7.5 (HIGH). The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) ...
How severe is CVE-2012-4399?
CVE-2012-4399 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4399?
Check the references section above for vendor advisories and patch information. Affected products include: Cakefoundation Cakephp.