Symfony Enabled Debug Mode Scanner

Stay Up To Date
Asset Type


Need Membership


Asset Verify


API Support


Estimate Time (Second)


Symfony Enabled Debug Mode Scanner Detail

The remote Symfony installations appears to have left the 'debug' interface enabled, allowing the disclosure and possible execution of arbitrary code. Information disclosed from this page can be used to gain additional information about the target system.

One of the main features of debug mode is the display of detailed error pages. If your app raises an exception when debug is True, Symfony will display a detailed traceback, including a lot of metadata about your environment, such as all the currently defined Symfony settings. If an attacker can successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in formulating targeted attacks against the system.

Some Advice for Common Problems

Never deploy a site into production with DEBUG turned on.

Need a Full Assessment?

Get help from professional hackers. Learn about our penetration test service now!

Request Pentest Service