Symfony Enabled Debug Mode Scanner

Details
Stay Up To Date
Asset Type

DOMAIN,IP,URL

Need Membership

Yes

Asset Verify

Yes

API Support

Yes

Estimate Time (Second)

5

Symfony Enabled Debug Mode Scanner Detail

The remote Symfony installations appears to have left the 'debug' interface enabled, allowing the disclosure and possible execution of arbitrary code. Information disclosed from this page can be used to gain additional information about the target system.

One of the main features of debug mode is the display of detailed error pages. If your app raises an exception when debug is True, Symfony will display a detailed traceback, including a lot of metadata about your environment, such as all the currently defined Symfony settings. If an attacker can successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in formulating targeted attacks against the system.

Some Advice for Common Problems

Never deploy a site into production with DEBUG turned on.

Community Discussions

Need a Full Assesment?

Get help from professional hackers. Learn about our penetration test service now!

Request Pentest Service