CVE-2015-2308

EPSS 0.54%

Symfony Vulnerable to PHP Eval Injection

發布日:2022/5/17修改日:2026/5/27
也稱為:GHSA-5c58-w9xc-qcj9DEBIAN-CVE-2015-2308

描述

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

受影響套件(3)

參考連結(11)