{"api_version":"1","generated_at":"2026-07-23T10:14:03+00:00","cve":"CVE-2013-4752","urls":{"html":"https://cve.report/CVE-2013-4752","api":"https://cve.report/api/cve/CVE-2013-4752.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-4752","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-4752"},"summary":{"title":"CVE-2013-4752","description":"Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-01-02 17:15:00","updated_at":"2020-01-10 19:25:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/61715","name":"http://www.securityfocus.com/bid/61715","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 18 Update: php-symfony2-HttpFoundation-2.2.5-1.fc18","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released","name":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Security releases: Symfony 2.0.24, 2.1.12, 2.2.5, and 2.3.3 released - Symfony","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html","name":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 19 Update: php-symfony2-HttpFoundation-2.2.5-1.fc19","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752","refsource":"MISC","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"995583 – (CVE-2013-4752) CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-4752","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-4752","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"4752","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4752","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4752","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4752","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"19","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4752","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"4752","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sensiolabs","cpe5":"symfony","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2013-4752","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released","url":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367"},{"refsource":"MISC","name":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html"},{"refsource":"MISC","name":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html"},{"refsource":"MISC","name":"http://www.securityfocus.com/bid/61715","url":"http://www.securityfocus.com/bid/61715"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373"},{"refsource":"MISC","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374"}]}},"nvd":{"publishedDate":"2020-01-02 17:15:00","lastModifiedDate":"2020-01-10 19:25:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"2.3.0","versionEndExcluding":"2.3.3","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"2.2.0","versionEndExcluding":"2.2.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"2.1.0","versionEndExcluding":"2.1.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0.0","versionEndExcluding":"2.0.24","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"4752","Ordinal":"64425","Title":"CVE-2013-4752","CVE":"CVE-2013-4752","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"4752","Ordinal":"1","NoteData":"Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.","Type":"Description","Title":null},{"CveYear":"2013","CveId":"4752","Ordinal":"2","NoteData":"2020-01-02","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"4752","Ordinal":"3","NoteData":"2020-01-02","Type":"Other","Title":"Modified"}]}}}