CVE Vulnerabilities

CVE-2012-2667

Published: Jun 07, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified database backed session classes.

Affected Software

Name Vendor Start Version End Version
Symfony Sensiolabs * 1.4.17 (including)
Symfony Sensiolabs 1.4.0 (including) 1.4.0 (including)
Symfony Sensiolabs 1.4.0-rc1 (including) 1.4.0-rc1 (including)
Symfony Sensiolabs 1.4.0-rc2 (including) 1.4.0-rc2 (including)
Symfony Sensiolabs 1.4.1 (including) 1.4.1 (including)
Symfony Sensiolabs 1.4.2 (including) 1.4.2 (including)
Symfony Sensiolabs 1.4.3 (including) 1.4.3 (including)
Symfony Sensiolabs 1.4.4 (including) 1.4.4 (including)
Symfony Sensiolabs 1.4.5 (including) 1.4.5 (including)
Symfony Sensiolabs 1.4.6 (including) 1.4.6 (including)
Symfony Sensiolabs 1.4.7 (including) 1.4.7 (including)
Symfony Sensiolabs 1.4.8 (including) 1.4.8 (including)
Symfony Sensiolabs 1.4.9 (including) 1.4.9 (including)
Symfony Sensiolabs 1.4.10 (including) 1.4.10 (including)
Symfony Sensiolabs 1.4.11 (including) 1.4.11 (including)
Symfony Sensiolabs 1.4.12 (including) 1.4.12 (including)
Symfony Sensiolabs 1.4.13 (including) 1.4.13 (including)
Symfony Sensiolabs 1.4.14 (including) 1.4.14 (including)
Symfony Sensiolabs 1.4.15 (including) 1.4.15 (including)
Symfony Sensiolabs 1.4.16 (including) 1.4.16 (including)
Symfony Ubuntu lucid *
Symfony Ubuntu upstream *

References