Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.
References
Link | Resource |
---|---|
http://jvndb.jvn.jp/jvndb/JVNDB-2015-000089 | Vendor Advisory |
http://jvn.jp/en/jp/JVN19578958/index.html | Vendor Advisory |
https://symfony.com/blog/cve-2015-2308-esi-code-injection | Patch Vendor Advisory |
http://www.securityfocus.com/bid/75357 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2015-06-24 03:59
Updated : 2016-12-02 19:04
NVD link : CVE-2015-2308
Mitre link : CVE-2015-2308
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
sensiolabs
- symfony