Quantcast
Channel: Files from Phil Taylor ≈ Packet Storm
Viewing all articles
Browse latest Browse all 22

Symfony 2 Unauthenticated Information Disclosure

$
0
0
The XMLEncoder component of Symfony version 2.0.x fails to disable external entities when parsing XML. In the Symfony2 framework the XML class may be used to deserialize objects or as part of a client/server API. By using external entities it is possible to include arbitrary files from the file system. Any application written in Symfony2 that parses user supplied XML is affected.

Viewing all articles
Browse latest Browse all 22

Trending Articles