CVE-2012-6432

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
VendorProductVersion
sensiolabssymfony
2.0.0
sensiolabssymfony
2.0.1
sensiolabssymfony
2.0.2
sensiolabssymfony
2.0.3
sensiolabssymfony
2.0.4
sensiolabssymfony
2.0.5
sensiolabssymfony
2.0.6
sensiolabssymfony
2.0.7
sensiolabssymfony
2.0.8
sensiolabssymfony
2.0.9
sensiolabssymfony
2.0.10
sensiolabssymfony
2.0.11
sensiolabssymfony
2.0.12
sensiolabssymfony
2.0.13
sensiolabssymfony
2.0.14
sensiolabssymfony
2.0.15
sensiolabssymfony
2.0.16
sensiolabssymfony
2.0.17
sensiolabssymfony
2.0.18
sensiolabssymfony
2.0.19
sensiolabssymfony
2.0.20
sensiolabssymfony
2.1.0
sensiolabssymfony
2.1.1
sensiolabssymfony
2.1.2
sensiolabssymfony
2.1.3
sensiolabssymfony
2.2:dev
𝑥
= Vulnerable software versions
Common Weakness Enumeration