Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2015-06-24T10:00:00
Updated: 2024-08-06T05:10:16.150Z
Reserved: 2015-03-16T00:00:00
Link: CVE-2015-2308
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-06-24T10:59:01.103
Modified: 2024-11-21T02:27:11.143
Link: CVE-2015-2308
Redhat
No data.