4.3
CVE-2012-2667
- EPSS 1.35%
- Veröffentlicht 07.06.2012 19:55:09
- Zuletzt bearbeitet 16.06.2026 23:41:50
- Erkennungen
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sensiolabs ≫ Symfony Version <= 1.4.17
Sensiolabs ≫ Symfony Version 1.4.0
Sensiolabs ≫ Symfony Version 1.4.0 Update rc1
Sensiolabs ≫ Symfony Version 1.4.0 Update rc2
Sensiolabs ≫ Symfony Version 1.4.1
Sensiolabs ≫ Symfony Version 1.4.2
Sensiolabs ≫ Symfony Version 1.4.3
Sensiolabs ≫ Symfony Version 1.4.4
Sensiolabs ≫ Symfony Version 1.4.5
Sensiolabs ≫ Symfony Version 1.4.6
Sensiolabs ≫ Symfony Version 1.4.7
Sensiolabs ≫ Symfony Version 1.4.8
Sensiolabs ≫ Symfony Version 1.4.9
Sensiolabs ≫ Symfony Version 1.4.10
Sensiolabs ≫ Symfony Version 1.4.11
Sensiolabs ≫ Symfony Version 1.4.12
Sensiolabs ≫ Symfony Version 1.4.13
Sensiolabs ≫ Symfony Version 1.4.14
Sensiolabs ≫ Symfony Version 1.4.15
Sensiolabs ≫ Symfony Version 1.4.16
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.35% | 0.678 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/49312
http://symfony.com/blog/security-release-symfony-1-4-18-released
http://trac.symfony-project.org/browser/tags/RELEASE_1_4_18/CHANGELOG
http://www.openwall.com/lists/oss-security/2012/06/04/1
http://www.openwall.com/lists/oss-security/2012/06/05/2
http://www.securityfocus.com/bid/53776
https://exchange.xforce.ibmcloud.com/vulnerabilities/76027