#VU40709 Code Injection in Symfony - CVE-2015-2308
Published: June 24, 2015 / Updated: August 9, 2020
Symfony
SensioLabs
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.