CVE-2013-5750

The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
friends_of_symfony_projectfosuserbundle
𝑥
≤ 1.3.2
friends_of_symfony_projectfosuserbundle
1.0.0
friends_of_symfony_projectfosuserbundle
1.1.0
friends_of_symfony_projectfosuserbundle
1.2.0
friends_of_symfony_projectfosuserbundle
1.2.1
friends_of_symfony_projectfosuserbundle
1.2.3
friends_of_symfony_projectfosuserbundle
1.2.4
friends_of_symfony_projectfosuserbundle
1.2.5
friends_of_symfony_projectfosuserbundle
1.3.0
friends_of_symfony_projectfosuserbundle
1.3.1
𝑥
= Vulnerable software versions
Common Weakness Enumeration