Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Symfony 安全绕过漏洞
Vulnerability Description
Sensio Labs Symfony是法国Sensio Labs公司的一套免费的、基于MVC架构的PHP开发框架。该框架提供常用的功能组件及工具,可用于快速创建复杂的WEB程序。 Symfony 2.0.20之前的2.0.x版本中存在漏洞,该漏洞源于始终在Routing和Security组件中的程序没有处理URL编码的数据。通过双编码字符串,远程攻击者利用该漏洞绕过预期的URI限制。
CVSS Information
N/A
Vulnerability Type
N/A