4.3
CVE-2012-2667
- EPSS 0.52%
- Published 07.06.2012 19:55:09
- Last modified 11.04.2025 00:51:21
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."
Data is provided by the National Vulnerability Database (NVD)
Sensiolabs ≫ Symfony Version <= 1.4.17
Sensiolabs ≫ Symfony Version1.4.0
Sensiolabs ≫ Symfony Version1.4.0 Updaterc1
Sensiolabs ≫ Symfony Version1.4.0 Updaterc2
Sensiolabs ≫ Symfony Version1.4.1
Sensiolabs ≫ Symfony Version1.4.2
Sensiolabs ≫ Symfony Version1.4.3
Sensiolabs ≫ Symfony Version1.4.4
Sensiolabs ≫ Symfony Version1.4.5
Sensiolabs ≫ Symfony Version1.4.6
Sensiolabs ≫ Symfony Version1.4.7
Sensiolabs ≫ Symfony Version1.4.8
Sensiolabs ≫ Symfony Version1.4.9
Sensiolabs ≫ Symfony Version1.4.10
Sensiolabs ≫ Symfony Version1.4.11
Sensiolabs ≫ Symfony Version1.4.12
Sensiolabs ≫ Symfony Version1.4.13
Sensiolabs ≫ Symfony Version1.4.14
Sensiolabs ≫ Symfony Version1.4.15
Sensiolabs ≫ Symfony Version1.4.16
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.52% | 0.639 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|