|
|
| |
| Symfony is prone to a session-fixation vulnerability. |
| |
Credit:
The information has been provided by Dmitri Groutso.
The original article can be found at: http://www.securityfocus.com/bid/53776
|
| |
Vulnerable Systems:
* SensioLabs Symfony 1.4.17
Immune Systems:
* SensioLabs Symfony 1.4.18
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Vendor Status:
Vendor had issued an update for this vulnerability
Patch Availability:
http://symfony.com/blog/security-release-symfony-1-4-18-released
CVE Information:
CVE-2011-4964
Disclosure Timeline:
Initial Release: May 30 2012
|
|
blog comments powered by
|