CVE-2010-4335
CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code
EPSS 55.2%
描述
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
如何修補 CVE-2010-4335
要修補 CVE-2010-4335,請將受影響套件升級到下列已修補版本。
- Debian/cakephp—升級至 1.3.2-1.1 或更新版本
- —升級至 1.3.6 或更新版本
CVE-2010-4335 正在被利用嗎?
可能 — EPSS 為 55.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 1.3.2-1.1
- >= 1.2.8, < 1.3.6