Back to Database
Status published
Medium
CVE-2012-5574
lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to...
Vulnerability Description
lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-5574
Credits & Attribution
No credits recorded in the NVD database.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=880240
- http://lists.fedoraproject.org/pipermail/package-announce/2012-December/093920.html
- http://lists.fedoraproject.org/pipermail/package-announce/2012-December/093698.html
- http://symfony.com/blog/security-release-symfony-1-4-20-released
- http://www.securityfocus.com/bid/56685
- https://bugs.gentoo.org/show_bug.cgi?id=444696
- http://www.osvdb.org/87869
- http://lists.fedoraproject.org/pipermail/package-announce/2012-December/093922.html
- http://secunia.com/advisories/51372
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80309
- http://www.openwall.com/lists/oss-security/2012/11/26/12
- http://trac.symfony-project.org/changeset/33598
More from sensiolabs
View All →CVE-2019-18889
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0...
Critical
9.8
CVE-2019-18888
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0...
High
7.5
CVE-2019-18887
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0...
High
8.1
CVE-2019-18886
An issue was discovered in Symfony 4.2.0 to 4.2.11 and...
Medium
5.3
CVE-2019-11325
An issue was discovered in Symfony before 4.2.12 and 4.3.x...
Critical
9.8
Affected Vendor
sensiolabs
View all reports →Affected Software
symfony
Vulnerable Versions:
0, 1.4.0, 1.4.1, 1.4.2, 1.4.3, 1.4.4, 1.4.5, 1.4.6, 1.4.7, 1.4.8, 1.4.9, 1.4.10, 1.4.11, 1.4.12, 1.4.13, 1.4.14, 1.4.15, 1.4.16, 1.4.17, 1.4.18
Timeline
Official Publish:
December 18th, 2012
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.