Nicolas Grekas
15 exploits
Active since Aug 2018
Symfony 2.0.0-4.4.49 - Session Fixation via HTTP Cache Set-Cookie Header
CVSS 5.9
Symfony <4.4.51, <5.4.31, <6.3.8 - XSS
CVSS 6.1
Symfony Http Foundation Web Cache Poisoning via X-Original-URL or X-Rewrite-URL Header
CVSS 6.5
Symfony <4.1.3 - Host Header Injection
CVSS 7.2
Symfony 2.7.0-2.7.50, 2.8.0-2.8.49, 3.0.0-3.4.25, 4.0.0-4.1.11, 4.2.0-4.2.6 - SQLi & RCE via Service ID
CVSS 9.8
Symfony < 2.8.50, 3.x < 3.4.26, 4.x < 4.1.12, 4.2.x < 4.2.7 - Arbitrary File Deletion via Unsafe Object Caching
CVSS 7.1
Symfony 2.7.0-2.7.50, 2.8.0-2.8.49, 3.0.0-3.4.25, 4.0.0-4.1.11, 4.2.0-4.2.6 - XSS via HTTP Method Override
CVSS 9.8
Symfony 2.0.0-4.4.49 - Insufficient Session Expiration via CSRF Token Preservation
CVSS 6.3
Symfony 2.0.0-4.4.49 - Insufficient Session Expiration via CSRF Token Preservation
CVSS 6.3
Symfony <4.4.51, <5.4.31, <6.3.8 - XSS
CVSS 6.1
Symfony 6.0.0-6.3.7 - Cross-Site Scripting in WebhookController Error Message
CVSS 6.1
symfony/http-client < 5.4.46 - Information Exposure via NoPrivateNetworkHttpClient
CVSS 3.1
Twig <3.11.2, <3.14.1 - Info Disclosure
CVSS 2.2
Symfony <5.4.50,6.4.29,7.3.7 - Path Traversal
CVSS 7.3
Symfony <5.4.51-8.0.5 - Code Injection
CVSS 6.3