« Volver al listado

CVE-2010-4335

Estado: ModificadaAlta (7.5)—

The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-4335",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2011-01-14T23:00:46.850",
  "references": [
    {
      "url": "http://malloc.im/CakePHP-unserialize.txt",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://packetstormsecurity.org/files/view/95847/burnedcake.py.txt",
      "tags": [
        "Exploit"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/42211",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://securityreason.com/securityalert/8026",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.exploit-db.com/exploits/16011",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.osvdb.org/69352",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://github.com/cakephp/cakephp/commit/e431e86aa4301ced4273dc7919b59362cbb353cb",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://malloc.im/CakePHP-unserialize.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.org/files/view/95847/burnedcake.py.txt",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/42211",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/8026",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.exploit-db.com/exploits/16011",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/69352",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/cakephp/cakephp/commit/e431e86aa4301ced4273dc7919b59362cbb353cb",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files."
    },
    {
      "lang": "es",
      "value": "la función _validatePost en libs/controller/components/security.php en CakePHP v1.3.x hasta la v1.3.5 y v1.2.8 permite a atacantes remotos modificar la caché interna de la aplicación y ejecutar código arbitrario a través de un valor data[_token][fields] debiadamente modificado, el cual es procesado por la función unserialize, como se ha demostrado mediante la modificación de la caché file_map para ejecutar archivos locales."
    }
  ],
  "lastModified": "2026-06-16T23:24:35.097",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cakefoundation:cakephp:1.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C65627A5-D154-48F5-8902-D66899ABC206"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.2.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A584BF0-397D-44C7-9F81-CC23EFBAA70B"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3:dev:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A61C888-8403-4C49-A2A9-8B4AB28518D0"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.0:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9003AC05-6B40-4362-B808-B05FFF4E7BB9"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.0:beta:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDCBE15B-B9CD-462A-9A60-A67B298B6416"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4520A728-DD2E-4FFA-8AA7-1A411336C7FE"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1537D8B-9A98-4825-9A2D-1834B01C3E04"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33E9CE1A-7B0E-4171-A525-820378DDB9AF"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.0:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40A4B932-BC79-4EBD-8582-3F35BCE566FF"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3914F5C9-25F0-4204-A817-5192326B37E9"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9C75332-BD3C-477E-9FEA-4BF1273DA0C4"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D94386AB-8C14-492A-9E67-C827E21440B6"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C66D697F-CEE2-43C9-B292-359CD77EC775"
            },
            {
              "criteria": "cpe:2.3:a:cakephp:cakephp:1.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EFC5BFAB-16F9-4B80-9BF0-31DE89FD3985"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}