Session Fixation Vulnerability in Symfony 1.4.18 and earlier versions

Session Fixation Vulnerability in Symfony 1.4.18 and earlier versions

CVE-2012-2667 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

Learn more about our Web App Pen Testing.