{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2020-01-02T16:07:55.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released"},{"tags":["x_refsource_MISC"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367"},{"tags":["x_refsource_MISC"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html"},{"tags":["x_refsource_MISC"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html"},{"tags":["x_refsource_MISC"],"url":"http://www.securityfocus.com/bid/61715"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373"},{"tags":["x_refsource_MISC"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2013-4752","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released","refsource":"CONFIRM","url":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752","refsource":"MISC","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367"},{"name":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html","refsource":"MISC","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html"},{"name":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html","refsource":"MISC","url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html"},{"name":"http://www.securityfocus.com/bid/61715","refsource":"MISC","url":"http://www.securityfocus.com/bid/61715"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373"},{"name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374","refsource":"MISC","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T16:52:27.085Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86367"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.securityfocus.com/bid/61715"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86365"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86366"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86368"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86369"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86370"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86371"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86372"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86373"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/86374"}]}]},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2013-4752","datePublished":"2020-01-02T16:07:55.000Z","dateReserved":"2013-07-02T00:00:00.000Z","dateUpdated":"2024-08-06T16:52:27.085Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}