2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2015-2308" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2015-06-24T10:59:01.103" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T02:27:11.143" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language=\"php\" attribute of a SCRIPT element."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de inyecci\u00f3n Eval en la clase HttpCache en HttpKernel en Symfony 2.x anterior a 2.3.27, 2.4.x y 2.5.x anterior a 2.5.11, y 2.6.x anterior a 2.6.6 permite a atacantes remotos ejecutar c\u00f3digo PHP arbitrario a trav\u00e9s de un atributo language='php' de un elemento SCRIPT."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:P/I:P/A:P" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-94"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "379F1431-3466-4263-8C02-D6541E593F65"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7CBEC708-96A2-43DD-88C0-9407ABB6D4FF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "56B52BED-2996-4C96-A348-98A8C72C8EA2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1C6279E7-F362-4C13-A965-908BCF9C30E3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5A101B27-9AE7-4C04-80BC-03A981217782"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3360BFF1-89ED-4294-A503-835C9C40C7D7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CE78FEA0-42E8-463C-9C7C-C778F712BB0F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AF5CEE9C-822C-491F-841C-218AA21C0AD1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "822F9083-5542-41AA-B9FA-1B43DE633340"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "165F68AE-AB34-4C20-88C6-56210548242B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B13BE7AA-72FD-402D-8919-BC5F23D03EFD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "34B1B511-5EBC-4301-A561-AE15B63DFC74"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.12:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8AF62D2D-2D62-4F15-83CD-F635DC838031"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.13:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B3A8431-356C-498F-AAEA-EC8D05D74877"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.14:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E53A27F2-9C3D-4670-BE1E-A1F6994EF1CA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.15:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "18DEB929-6B35-488B-80BF-70448BF7A6F0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.16:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2EB03E2D-F137-4CBA-887D-D1461735C958"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.17:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D37175A7-C937-4758-8EED-BE24C43AA115"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.18:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E1EF598F-F8F6-4980-BC76-C2FAF8FE7AF8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.19:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C3CD1432-1C91-4DFE-86E0-E5E97775A425"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "768F171C-3625-4696-ACEC-A10FA70F6BF7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "55B048CA-DDD8-473A-88D5-1AA36B134F1B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.0.22:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "23EE797D-54E8-4063-82DB-3D55027DC7DB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D7CD9AD6-5303-41C3-848B-504BFC03307D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1175DE26-53D0-4411-8416-C60602A097D3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "88E95571-E3F3-4D8F-A03C-C95317D7C4CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "08CEC939-1319-475E-AE3B-5BFB3D05A38A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B1DB3966-94A2-4154-8449-09C4E44127D1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E5E16EB7-BA1C-4B49-A466-68EC0067D432"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1DD23E22-222D-4933-B534-B1E91807D6BB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.1.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9D80A3A8-C230-4F81-8852-21985FB6562C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F79CDFB3-9BE8-4D29-90D0-9A14A7478CE6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "EE2FA705-1052-4938-9177-A16CC317C0A4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "078D5869-B3E3-4046-A942-B63921AD19DB"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "098D9DD8-2113-48BA-A31C-75ED36F010CC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DCEE5787-51E2-40EC-8B6E-FCA049E88381"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2CFBB031-DD47-41AB-BC38-D006F6C94FCD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "37873421-811B-45C7-9C75-CF92DEBD8DC3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B692349E-6ACF-4F39-B334-EB649C03C008"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9FCDA8E2-61B1-49D1-B99D-3FDB640B3D3F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B7B2F5DA-6679-4720-A296-FD06A0AE62C2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.2.11:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "68CFDDF0-86AF-4360-BBA3-C8D4D23F28E2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.19:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5B629031-7AC2-4918-9FEC-C9D26EBB0161"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.20:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "397E0404-9856-45C1-B12D-058E84F3FA3C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.21:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A2EC987B-3C4D-4575-9BC8-9AFB794A20E7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.22:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DE17FB48-06AA-4275-9F3A-0CF008C9C86B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.23:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "39F81F64-CCF2-4CB1-9504-153267839BEE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.24:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7B1244EA-78F7-4501-9E42-52C77CE37963"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.25:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CBCD0661-41FA-4F89-A1D8-C50BE232D36D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.3.26:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1AC87263-68E3-4BF8-8ED7-C40CC2F8CE2A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "2298A972-5CF9-477E-997D-8CD8CF7C68C1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "429897EE-A2AB-4D53-91DE-14419270C387"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "46DF9D9B-F5DC-48B9-9C63-BE3B61CBD30E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7014696F-318B-42DE-BD9A-881B6E849EB4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0899FE78-4E32-4D6A-AFE5-59D8DDA4DEAA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9A3E4A96-731B-46AA-B686-777841BC31C2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D3F1B7BB-F623-49A9-86BD-F55F8CE4698E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "34F5B9AE-C086-43C0-AE0D-A7E1AF0EA4FD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "3FE35E75-315C-472B-B8C3-4E9AF9C5421F"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.4.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "360EFC8C-6FD2-48B1-A3E9-C16867B05F17"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F42DB1A7-3DD3-48FE-9B0B-48866ACAB861"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.2:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "478385F1-2EB7-45D4-BBCC-D0EAA0F1A793"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1EB3201A-180F-49D9-8436-7D3181A5B40D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "97E35964-8D47-4146-AF91-C5EC0A8E1801"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "01076190-7FDF-4A9C-99C9-A1F153BFFA09"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.6:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8D6EBF05-F0C6-4B36-8B5E-BF1793364AE8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.7:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0FE1BB71-C1E8-4957-B5A6-E7B24A3FEC76"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.8:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BD415B94-A1DA-4483-8F39-56BDF805A7DA"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.9:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "4EAC5594-43BE-4DA4-9420-C070F6C5C77C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.5.10:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BFCA2A46-50CD-4C31-836C-F9D922810D3D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0F13A190-1F97-4D7B-826A-E976934AE82B"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.6.1:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "27770F28-584A-48E1-B885-6C6D17F546ED"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.6.3:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C177DF32-F356-483C-82E5-8FCC68D89A74"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.6.4:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C6D9461C-A049-48EC-BB3E-FD3212C82795"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sensiolabs:symfony:2.6.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "0F7EF330-714D-42E4-A2CF-406B84F3945B"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://jvn.jp/en/jp/JVN19578958/index.html" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000089" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/75357" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://symfony.com/blog/cve-2015-2308-esi-code-injection" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "http://jvn.jp/en/jp/JVN19578958/index.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000089" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
} ,
{
"url" : "http://www.securityfocus.com/bid/75357" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://symfony.com/blog/cve-2015-2308-esi-code-injection" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}