cbcvebase.
CVE-2012-6431
published 2012-12-27

CVE-2012-6431: Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass…

PriorityP434medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
1.88%
77.1th percentile
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

Affected

24 ranges
VendorProductVersion rangeFixed in
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
sensiolabssymfony
symfonyhttp-foundation>= 2.0.0 < 2.0.192.0.19
symfonyrouting>= 2.0.0 < 2.0.192.0.19
symfonysecurity>= 2.0.0 < 2.0.192.0.19
symfonysymfony>= 2.0.0 < 2.0.192.0.19
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.