Moderate severityNVD Advisory· Published Aug 10, 2006· Updated Apr 16, 2026
CVE-2006-4067
CVE-2006-4067
Description
Cross-site scripting (XSS) vulnerability in cake/libs/error.php in CakePHP before 1.1.7.3363 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in a 404 ("Not Found") error page. NOTE: some of these details are obtained from third party information.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cakephp/cakephpPackagist | >= 1.0.1.2708, < 1.1.7.3363 | 1.1.7.3363 |
Affected products
5cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:cakephp:cakephp:*:*:*:*:*:*:*:*range: <=1.1.6.3264
- cpe:2.3:a:cakephp:cakephp:1.0.1.2708:*:*:*:*:*:*:*
- cpe:2.3:a:cakephp:cakephp:1.1.3.2967:*:*:*:*:*:*:*
- cpe:2.3:a:cakephp:cakephp:1.1.4.3104:*:*:*:*:*:*:*
- cpe:2.3:a:cakephp:cakephp:1.1.5.3148:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- cakeforge.org/frs/shownotes.phpnvdPatch
- secunia.com/advisories/21383nvdPatchVendor Advisory
- github.com/advisories/GHSA-vc29-mvwv-wpcqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2006-4067ghsaADVISORY
- exchange.xforce.ibmcloud.com/vulnerabilities/28256nvdWEB
- www.securityfocus.com/bid/19372nvd
- www.vupen.com/english/advisories/2006/3172nvd
News mentions
0No linked articles in our index yet.