CVE Vulnerabilities

CVE-2012-5574

Published: Dec 18, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

Affected Software

NameVendorStart VersionEnd Version
SymfonySensiolabs*1.4.19 (including)
SymfonySensiolabs1.4.0 (including)1.4.0 (including)
SymfonySensiolabs1.4.0-rc1 (including)1.4.0-rc1 (including)
SymfonySensiolabs1.4.0-rc2 (including)1.4.0-rc2 (including)
SymfonySensiolabs1.4.1 (including)1.4.1 (including)
SymfonySensiolabs1.4.2 (including)1.4.2 (including)
SymfonySensiolabs1.4.3 (including)1.4.3 (including)
SymfonySensiolabs1.4.4 (including)1.4.4 (including)
SymfonySensiolabs1.4.5 (including)1.4.5 (including)
SymfonySensiolabs1.4.6 (including)1.4.6 (including)
SymfonySensiolabs1.4.7 (including)1.4.7 (including)
SymfonySensiolabs1.4.8 (including)1.4.8 (including)
SymfonySensiolabs1.4.9 (including)1.4.9 (including)
SymfonySensiolabs1.4.10 (including)1.4.10 (including)
SymfonySensiolabs1.4.11 (including)1.4.11 (including)
SymfonySensiolabs1.4.12 (including)1.4.12 (including)
SymfonySensiolabs1.4.13 (including)1.4.13 (including)
SymfonySensiolabs1.4.14 (including)1.4.14 (including)
SymfonySensiolabs1.4.15 (including)1.4.15 (including)
SymfonySensiolabs1.4.16 (including)1.4.16 (including)
SymfonySensiolabs1.4.17 (including)1.4.17 (including)
SymfonySensiolabs1.4.18 (including)1.4.18 (including)

References