CVE-2013-1348: Code Injection
Ability to enable/disable PHP parsing in Yaml::parse()
Other sources
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
— GitHub
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1348?
CVE-2013-1348 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2013-1348?
To fix CVE-2013-1348, you should upgrade your Symfony version to 2.0.22 or later.
Which Symfony versions are affected by CVE-2013-1348?
CVE-2013-1348 affects Symfony versions from 2.0.0 up to 2.0.21.
Can CVE-2013-1348 be exploited remotely?
Yes, CVE-2013-1348 can be exploited remotely by attackers to execute arbitrary PHP code.
Is CVE-2013-1348 related to any other vulnerabilities?
CVE-2013-1348 is related to CVE-2013-1397 but addresses a different issue regarding PHP code execution.