Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SensioLabs Symfony会话固定漏洞
Vulnerability Description
SensioLabs Symfony 1.4.18之前版本的lib/user/sfBasicSecurityUser.class.php中存在会话固定漏洞。远程攻击者可利用该漏洞借助与regenerate方法和未明“数据库备份会话类”相关的向量劫持网络会话。
CVSS Information
N/A
Vulnerability Type
N/A