CVE-2006-4067: XSS
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4067?
CVE-2006-4067 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-4067?
To fix CVE-2006-4067, upgrade CakePHP to version 1.1.7.3363 or later.
What versions of CakePHP are affected by CVE-2006-4067?
CVE-2006-4067 affects CakePHP versions prior to 1.1.7.3363, including versions 1.0.1.2708 and 1.1.6.3264.
What type of attack does CVE-2006-4067 allow?
CVE-2006-4067 allows remote attackers to execute cross-site scripting (XSS) attacks by injecting arbitrary web scripts through the URL.
Is it possible to exploit CVE-2006-4067 on a live website?
Yes, if a vulnerable version of CakePHP is running on a live website, attackers can exploit CVE-2006-4067 to execute malicious scripts.