We found results for “”
CVE-2015-2308
Good to know:
Date: June 24, 2015
Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.
Language: PHP
Severity Score
Related Resources (12)
Severity Score
Weakness Type (CWE)
Improper Control of Generation of Code ('Code Injection')
CWE-94Top Fix
Upgrade Version
Upgrade to version twig/twig - v2.1.0;symfony/symfony - 2.5.x-dev;symfony/symfony - 2.3.x-dev;symfony/symfony - v2.5.11;symfony/symfony - v2.0.0PR8;symfony/symfony - v2.3.27;symfony/symfony - dev-pull/44976;moc-framework/mark-v - 0.1.2;mejor/cms - dev-backend;expstudio/laravel-4-startup-boilerplate - no_fix;korstiaan/drupal-mirror - no_fix;anis/mobsurvey-bundle - no_fix;quberik/application-for-domotehnika - no_fix;emiberea/day1-task-no2 - no_fix;lukaswilkeer/silex-silicon - 0.5;avro/blog-bundle - v0.1.1;symfony/http-kernel - 2.5.x-dev;symfony/http-kernel - v2.5.11;symfony/http-kernel - v2.3.27;symfony/http-kernel - 2.3.x-dev;linhecheng/cmlphp - v2.3.27;linhecheng/cmlphp - 2.5.x-dev;linhecheng/cmlphp - 2.3.x-dev;zzh-php/lib - no_fix;adkgamers/bfadmincp - v2.0.0;speedovation/laravelmart - dev-Laravel5;speedovation/laravelmart - 0.2;vijaycs85/coverage-report - 8.0.0-beta10;vijaycs85/coverage-report - 8.0.0-beta4;shopware/shopware - dev-dependabot/composer/recovery/common/voku/anti-xss-4.1.42;jamc92/precursor-silex - no_fix;travis/silex - no_fix;webguerilla/pgpmailer - no_fix;my-oos/my-oos - v2.0.62;kbrabrand/silex-neo4j - 1.0.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | LOW |
| Integrity (I): | LOW |
| Availability (A): | LOW |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | MEDIUM |
| Authentication (AU): | NONE |
| Confidentiality (C): | PARTIAL |
| Integrity (I): | PARTIAL |
| Availability (A): | PARTIAL |
| Additional information: |
Vulnerabilities
Projects
Contact Us


