|
|
| |
|
| |
php-symfony-symfony: information disclosure
| Package(s): | php-symfony-symfony |
CVE #(s): | CVE-2012-5574
|
| Created: | December 6, 2012 |
Updated: | December 12, 2012 |
| Description: |
From the Red Hat bugzilla:
An information disclosure flaw was found in the way Symfony, a open-source PHP web framework, sanitized certain HTTP POST request values. A remote attacker could use this flaw to obtain (unauthorized) read access to arbitrary system files, readable with the privileges of the web server process. |
| Alerts: |
|
( Log in to post comments)
|
|
|