CVE Vulnerabilities

CVE-2012-6432

Published: Dec 27, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

Affected Software

NameVendorStart VersionEnd Version
SymfonySensiolabs2.0.0 (including)2.0.0 (including)
SymfonySensiolabs2.0.1 (including)2.0.1 (including)
SymfonySensiolabs2.0.2 (including)2.0.2 (including)
SymfonySensiolabs2.0.3 (including)2.0.3 (including)
SymfonySensiolabs2.0.4 (including)2.0.4 (including)
SymfonySensiolabs2.0.5 (including)2.0.5 (including)
SymfonySensiolabs2.0.6 (including)2.0.6 (including)
SymfonySensiolabs2.0.7 (including)2.0.7 (including)
SymfonySensiolabs2.0.8 (including)2.0.8 (including)
SymfonySensiolabs2.0.9 (including)2.0.9 (including)
SymfonySensiolabs2.0.10 (including)2.0.10 (including)
SymfonySensiolabs2.0.11 (including)2.0.11 (including)
SymfonySensiolabs2.0.12 (including)2.0.12 (including)
SymfonySensiolabs2.0.13 (including)2.0.13 (including)
SymfonySensiolabs2.0.14 (including)2.0.14 (including)
SymfonySensiolabs2.0.15 (including)2.0.15 (including)
SymfonySensiolabs2.0.16 (including)2.0.16 (including)
SymfonySensiolabs2.0.17 (including)2.0.17 (including)
SymfonySensiolabs2.0.18 (including)2.0.18 (including)
SymfonySensiolabs2.0.19 (including)2.0.19 (including)
SymfonySensiolabs2.0.20 (including)2.0.20 (including)

References