4.3
CVSSv2

CVE-2012-2667

Published: 07/06/2012 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony prior to 1.4.18 allows remote malicious users to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

Vulnerable Product Search on Vulmon Subscribe to Product

sensiolabs symfony 1.4.14

sensiolabs symfony 1.4.13

sensiolabs symfony 1.4.6

sensiolabs symfony 1.4.5

sensiolabs symfony 1.4.16

sensiolabs symfony 1.4.15

sensiolabs symfony 1.4.8

sensiolabs symfony 1.4.7

sensiolabs symfony 1.4.0

sensiolabs symfony 1.4.12

sensiolabs symfony 1.4.11

sensiolabs symfony 1.4.4

sensiolabs symfony 1.4.3

sensiolabs symfony 1.4.2

sensiolabs symfony

sensiolabs symfony 1.4.10

sensiolabs symfony 1.4.9

sensiolabs symfony 1.4.1