Vulnerabilities
Vulnerable Software
Getsymphony:  >> Symphony  >> 2.6.4  Security Vulnerabilities
Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.
CVSS Score
8.8
EPSS Score
0.058
Published
2017-04-11
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters.
CVSS Score
5.3
EPSS Score
0.013
Published
2017-01-20
Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-01-20


Contact Us

Shodan ® - All rights reserved