Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4781
HistoryJul 28, 2017 - 8:49 a.m.

Arbitrary Code Injection

2017-07-2808:49:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.005 Low

EPSS

Percentile

77.1%

Symfony is vulnerable to arbitrary code injection attacks. A malicious user can inject and execute arbitrary PHP code with a language=“php” attribute of a SCRIPT element through the Symfony\Component\HttpKernel\HttpCache class. This vulnerability only affects applications with ESI or SSI support enabled.