Логотип exploitDog
product: "symfony"
Консоль
Логотип exploitDog

exploitDog

product: "symfony"

Количество 255

Количество 255

nvd логотип

CVE-2015-4050

больше 10 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
EPSS: Высокий
debian логотип

CVE-2015-4050

больше 10 лет назад

FragmentListener in the HttpKernel component in Symfony 2.3.19 through ...

CVSS2: 4.3
EPSS: Высокий
ubuntu логотип

CVE-2015-2308

больше 10 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2308

больше 10 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2308

больше 10 лет назад

Eval injection vulnerability in the HttpCache class in HttpKernel in S ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-5958

почти 11 лет назад

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-5958

почти 11 лет назад

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2. ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-4752

почти 6 лет назад

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2013-4751

около 6 лет назад

php-symfony2-Validator has loss of information during serialization

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2013-1397

больше 11 лет назад

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-1397

больше 11 лет назад

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote atta ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-1348

больше 11 лет назад

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-1348

больше 11 лет назад

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attacke ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-6432

почти 13 лет назад

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-6431

почти 13 лет назад

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-5574

почти 13 лет назад

lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-2667

больше 13 лет назад

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-2667

больше 13 лет назад

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS2: 4.3
EPSS: Низкий
fstec логотип

BDU:2024-10934

больше 1 года назад

Уязвимость класса FormLoginAuthenticator программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю обойти процедуру аутентификации и вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-08236

почти 2 года назад

Уязвимость функции SessionStrategyListener программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS2: 4.3
76%
Высокий
больше 10 лет назад
debian логотип
CVE-2015-4050

FragmentListener in the HttpKernel component in Symfony 2.3.19 through ...

CVSS2: 4.3
76%
Высокий
больше 10 лет назад
ubuntu логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2015-2308

Eval injection vulnerability in the HttpCache class in HttpKernel in S ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

CVSS2: 5
0%
Низкий
почти 11 лет назад
debian логотип
CVE-2013-5958

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2. ...

CVSS2: 5
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2013-4752

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

CVSS3: 6.1
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2013-4751

php-symfony2-Validator has loss of information during serialization

CVSS3: 8.1
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2013-1397

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-1397

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote atta ...

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2013-1348

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2013-1348

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attacke ...

CVSS2: 7.5
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2012-6432

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

CVSS2: 6.8
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-6431

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

CVSS2: 6.4
0%
Низкий
почти 13 лет назад
nvd логотип
CVE-2012-5574

lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

CVSS2: 5
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2012-2667

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2012-2667

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
fstec логотип
BDU:2024-10934

Уязвимость класса FormLoginAuthenticator программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю обойти процедуру аутентификации и вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-08236

Уязвимость функции SessionStrategyListener программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.5
1%
Низкий
почти 2 года назад

Уязвимостей на страницу