Symfony2 XML Parsing Local File Disclosure Vulnerability
BID:52302
Info
Symfony2 XML Parsing Local File Disclosure Vulnerability
| Bugtraq ID: | 52302 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 05 2012 12:00AM |
| Updated: | Mar 05 2012 12:00AM |
| Credit: | Phil Taylor from Sense of Security Labs. |
| Vulnerable: |
SensioLabs Symfony2 2.0.10 |
| Not Vulnerable: |
SensioLabs Symfony2 2.0.11 |
Discussion
Symfony2 XML Parsing Local File Disclosure Vulnerability
Symfony2 is prone to a local file-disclosure vulnerability.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Symfony2 2.0.10 and prior versions are vulnerable.
Symfony2 is prone to a local file-disclosure vulnerability.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Symfony2 2.0.10 and prior versions are vulnerable.
References
Symfony2 XML Parsing Local File Disclosure Vulnerability
References:
References:
- Symfony2 Homepage (SensioLabs)
- Symfony2 Local File Disclosure - Security Advisory - SOS-12-002 (Phil Taylor)