CVEs Blog | G5 Cyber Security

CVE-2015-2308 – Eval injection vulnerability in the HttpCache class in HttpKernel in Symf

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language=”php” attribute of a SCRIPT element.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2308

Reference (s):

Exit mobile version