Looking for the vulnerability index of Invicti's legacy products?
CakePHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4399) - Vulnerability Database

CakePHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4399)

Description

The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.

References

Related Vulnerabilities