Vulnerability record · CVE-2010-4335 · published 14 January 2011
CVE-2010-4335: CakePHP _validatePost unserialize flaw enables remote code execution
Cakefoundation · Cakephp
The _validatePost function in CakePHP's security component passes the attacker-controlled data[_Token][fields] value to unserialize without validation. A remote attacker can use this to alter the internal Cake cache and cause arbitrary local files to be executed. The flaw affects CakePHP 1.3.x through 1.3.5 and 1.2.8.
Description
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows remote attackers to modify the internal Cake cache and execute arbitrary code via a crafted data[_Token][fields] value that is processed by the unserialize function, as demonstrated by modifying the file_map cache to execute arbitrary local files.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit code and very high EPSS, though not in CISA KEV.
What it is
The _validatePost function in CakePHP's security component passes the attacker-controlled data[_Token][fields] value to unserialize without validation. A remote attacker can use this to alter the internal Cake cache and cause arbitrary local files to be executed. The flaw affects CakePHP 1.3.x through 1.3.5 and 1.2.8.
Impact
An unauthenticated remote attacker can modify the framework's internal cache and achieve arbitrary code execution on the server. This gives full control over the application and potentially the host.
Attack surface
Reached over the network through crafted HTTP requests containing a malicious data[_Token][fields] value; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists (references tagged Exploit, including a Packet Storm script and an Exploit-DB entry), and EPSS is 0.55204 (99th percentile), though the CVE is not listed in CISA KEV.
What to do
- Upgrade CakePHP to a version containing the fix commit e431e86aa4301ced4273dc7919b59362cbb353cb or later.
- If immediate upgrade is not possible, avoid passing untrusted input to unserialize in the security component and validate the data[_Token][fields] parameter strictly.
- Restrict write access to the Cake cache directory and monitor it for unexpected changes.
- Apply the vendor advisory guidance from Secunia advisory 42211.
Detection
- Inspect web requests for unusual or oversized data[_Token][fields] values, especially serialized PHP object payloads.
- Monitor the Cake cache directory for unexpected file creation or modification.
- Alert on outbound or local file execution activity originating from the web server process following requests to CakePHP endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-4335 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-4335), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.