CVE-2013-1348
published 2014-06-02CVE-2013-1348: The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.62%
73.4th percentile
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Symfony Arbitrary PHP code Execution
osv·2022-05-17·CVSS 7.5
CVE-2013-1397 [HIGH] Symfony Arbitrary PHP code Execution
Symfony Arbitrary PHP code Execution
Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.
GHSA
Symphony Vulnerable to PHP Code Injection via YAML Parsing
ghsa·2022-05-17·CVSS 7.5
CVE-2013-1348 [HIGH] CWE-94 Symphony Vulnerable to PHP Code Injection via YAML Parsing
Symphony Vulnerable to PHP Code Injection via YAML Parsing
The `Yaml::parse` function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
GHSA
Symfony Arbitrary PHP code Execution
ghsa·2022-05-17·CVSS 7.5
CVE-2013-1397 [HIGH] CWE-94 Symfony Arbitrary PHP code Execution
Symfony Arbitrary PHP code Execution
Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.
OSV
Symphony Vulnerable to PHP Code Injection via YAML Parsing
osv·2022-05-17·CVSS 7.5
CVE-2013-1348 [HIGH] Symphony Vulnerable to PHP Code Injection via YAML Parsing
Symphony Vulnerable to PHP Code Injection via YAML Parsing
The `Yaml::parse` function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/51980http://symfony.com/blog/security-release-symfony-2-0-22-and-2-1-7-releasedhttp://www.securityfocus.com/bid/57574https://exchange.xforce.ibmcloud.com/vulnerabilities/81550http://secunia.com/advisories/51980http://symfony.com/blog/security-release-symfony-2-0-22-and-2-1-7-releasedhttp://www.securityfocus.com/bid/57574https://exchange.xforce.ibmcloud.com/vulnerabilities/81550
2014-06-02
Published