CVE-2015-2308
EPSS 0.54%Symfony Vulnerable to PHP Eval Injection
發布日:2022/5/17修改日:2026/5/27
描述
Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.
受影響套件(3)
- Debian/symfonyfrom 0, < 2.3.21+dfsg-4
- Packagist/symfony/http-kernel>= 2.0.0, < 2.3.27
- Packagist/symfony/symfony>= 2.0.0, < 2.3.27
參考連結(11)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2015-2308
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2015-2308
- PATCHhttps://github.com/symfony/symfony
- WEBhttp://jvndb.jvn.jp/jvndb/JVNDB-2015-000089
- WEBhttp://jvn.jp/en/jp/JVN19578958/index.html
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2015-2308.yaml
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2015-2308.yaml
- WEBhttps://github.com/symfony/symfony/pull/14167/commits/195c57e1f50765aff33137689b16e126a689056a
- WEBhttps://symfony.com/blog/cve-2015-2308-esi-code-injection
- WEBhttps://symfony.com/cve-2015-2308
- WEBhttps://web.archive.org/web/20200228084751/http://www.securityfocus.com/bid/75357