Vulnerabilities > Getsymphony > High

DATE CVE VULNERABILITY TITLE RISK
2016-06-30 CVE-2016-4309 Unspecified vulnerability in Getsymphony Symphony 2.6.7
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.
network
high complexity
getsymphony
7.6
2010-09-17 CVE-2010-3458 SQL Injection vulnerability in Getsymphony Symphony 2.0.7/2.1.1
SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/.
network
low complexity
getsymphony CWE-89
7.5
2010-06-03 CVE-2010-2143 Path Traversal vulnerability in Getsymphony Symphony 2.0.7
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a ..
network
low complexity
getsymphony CWE-22
7.5