Symfony CVE-2012-5574 Arbitrary File Access Vulnerability
BID:56685
Info
Symfony CVE-2012-5574 Arbitrary File Access Vulnerability
| Bugtraq ID: | 56685 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5574 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2012 12:00AM |
| Updated: | May 07 2015 05:13PM |
| Credit: | Uli Hecht |
| Vulnerable: |
SensioLabs Symfony 1.4.19 SensioLabs Symfony 1.4.18 SensioLabs Symfony 1.4.17 Gentoo Linux |
| Not Vulnerable: |
SensioLabs Symfony 1.4.20 |
Discussion
Symfony CVE-2012-5574 Arbitrary File Access Vulnerability
Symfony is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to read arbitrary files in the context of the web server process, which may aid in further attacks.
Symfony versions prior to 1.4.20 are vulnerable.
Symfony is prone to an arbitrary file-access vulnerability.
An attacker can exploit this issue to read arbitrary files in the context of the web server process, which may aid in further attacks.
Symfony versions prior to 1.4.20 are vulnerable.
Exploit / POC
Symfony CVE-2012-5574 Arbitrary File Access Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Symfony CVE-2012-5574 Arbitrary File Access Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.