6.8
CVSSv2

CVE-2015-8124

Published: 07/12/2015 Updated: 09/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x prior to 2.3.35, 2.6.x prior to 2.6.12, and 2.7.x prior to 2.7.7 allows remote malicious users to hijack web sessions via a session id.

Vulnerable Product Search on Vulmon Subscribe to Product

sensiolabs symfony 2.3.24

sensiolabs symfony 2.3.33

sensiolabs symfony 2.3.2

sensiolabs symfony 2.3.8

sensiolabs symfony 2.3.21

sensiolabs symfony 2.3.7

sensiolabs symfony 2.3.14

sensiolabs symfony 2.3.12

sensiolabs symfony 2.3.17

sensiolabs symfony 2.6.6

sensiolabs symfony 2.6.9

sensiolabs symfony 2.7.3

sensiolabs symfony 2.7.2

sensiolabs symfony 2.3.27

sensiolabs symfony 2.3.32

sensiolabs symfony 2.3.19

sensiolabs symfony 2.3.6

sensiolabs symfony 2.3.4

sensiolabs symfony 2.3.31

sensiolabs symfony 2.3.5

sensiolabs symfony 2.3.22

sensiolabs symfony 2.3.10

sensiolabs symfony 2.6.8

sensiolabs symfony 2.6.3

sensiolabs symfony 2.6.10

sensiolabs symfony 2.6.11

sensiolabs symfony 2.7.4

sensiolabs symfony 2.3.25

sensiolabs symfony 2.3.26

sensiolabs symfony 2.3.9

sensiolabs symfony 2.3.16

sensiolabs symfony 2.3.23

sensiolabs symfony 2.3.28

sensiolabs symfony 2.3.13

sensiolabs symfony 2.3.20

sensiolabs symfony 2.3.18

sensiolabs symfony 2.6.0

sensiolabs symfony 2.6.2

sensiolabs symfony 2.6.1

sensiolabs symfony 2.6.7

sensiolabs symfony 2.7.5

sensiolabs symfony 2.7.0

sensiolabs symfony 2.3.30

sensiolabs symfony 2.3.11

sensiolabs symfony 2.3.34

sensiolabs symfony 2.3.15

sensiolabs symfony 2.3.3

sensiolabs symfony 2.3.1

sensiolabs symfony 2.3.0

sensiolabs symfony 2.3.29

sensiolabs symfony 2.6.4

sensiolabs symfony 2.6.5

sensiolabs symfony 2.7.1

sensiolabs symfony 2.7.6

Vendor Advisories

Several vulnerabilities have been discovered in symfony, a framework to create websites and web applications The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8124 The RedTeam Pentesting GmbH team discovered a session fixation vulnerability within the Remember Me login feature, allowing an at ...

Exploits

Symfony PHP Framework versions 230 to 2334, 260 to 2611, and 270 to 276 suffers from a session fixation vulnerability ...