CVE-2015-2308

Source
https://cve.org/CVERecord?id=CVE-2015-2308
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-2308.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2015-2308
Aliases
Downstream
Published
2015-06-24T10:59:01Z
Modified
2026-04-10T03:46:14.369591Z
Summary
[none]
Details

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

References

Affected packages