The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2022-10-03T16:15:34

Updated: 2022-10-03T16:15:34

Reserved: 2022-10-03T00:00:00


Link: CVE-2012-4399

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-10-09T23:55:05.047

Modified: 2024-02-15T03:23:23.083


Link: CVE-2012-4399

JSON object: View

cve-icon Redhat Information

No data.

CWE