S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Dec 16, 2023

Symfony Enabled Debug Mode Scanner

The remote Symfony installations appears to have left the 'debug' interface enabled, allowing the disclosure and possible execution of arbitrary code. Information disclosed from this page can be used to gain additional information about the target system.

Est. Time~5 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
6.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
Detail

One of the main features of debug mode is the display of detailed error pages. If your app raises an exception when debug is True, Symfony will display a detailed traceback, including a lot of metadata about your environment, such as all the currently defined Symfony settings. If an attacker can successfully start a remote debugging session, this is likely to disclose sensitive information about the web application and supporting infrastructure that may be valuable in formulating targeted attacks against the system.

Solution Advice

Never deploy a site into production with DEBUG turned on.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Online Symfony Enabled Debug Mode Scanner | S4E