[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251625

 
 

909

 
 

196370

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-18343 -- symfony

ID: oval:org.secpod.oval:def:2000470Date: (C)2019-06-02   (M)2024-05-20
Class: VULNERABILITYFamily: unix




** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor"s position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.

Platform:
Debian 8.x
Debian 9.x
Product:
php-symfony-browser-kit
Reference:
CVE-2017-18343
CVE    1
CVE-2017-18343
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:symfony:php-symfony-browser-kit

© SecPod Technologies