CakePHP XML External Entity Injection Vulnerability
BID:54474
Info
CakePHP XML External Entity Injection Vulnerability
| Bugtraq ID: | 54474 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-4399 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2012 12:00AM |
| Updated: | Oct 11 2012 07:30PM |
| Credit: | Pawel h0wl Wylecial |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
CakePHP XML External Entity Injection Vulnerability
CakePHP is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information from local files on computers running the vulnerable application and carry out other attacks.
CakePHP 2.0 through version 2.2.0-RC2 are vulnerable.
CakePHP is prone to an XML External Entity injection vulnerability.
Attackers can exploit this issue to obtain potentially sensitive information from local files on computers running the vulnerable application and carry out other attacks.
CakePHP 2.0 through version 2.2.0-RC2 are vulnerable.
Exploit / POC
CakePHP XML External Entity Injection Vulnerability
The following example code is available:
The following example code is available:
Solution / Fix
CakePHP XML External Entity Injection Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.