Back to Database
Status published
High
CVE-2013-1348
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers...
Vulnerability Description
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-1348
Credits & Attribution
No credits recorded in the NVD database.
References
More from sensiolabs
View All →CVE-2019-18889
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0...
Critical
9.8
CVE-2019-18888
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0...
High
7.5
CVE-2019-18887
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0...
High
8.1
CVE-2019-18886
An issue was discovered in Symfony 4.2.0 to 4.2.11 and...
Medium
5.3
CVE-2019-11325
An issue was discovered in Symfony before 4.2.12 and 4.3.x...
Critical
9.8
Affected Vendor
sensiolabs
View all reports →Affected Software
symfony
Vulnerable Versions:
2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16, 2.0.17, 2.0.18, 2.0.19, 2.0.20, 2.0.21
Timeline
Official Publish:
June 2nd, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.