High severityNVD Advisory· Published Mar 30, 2015· Updated Jun 17, 2026
CVE-2015-2171
CVE-2015-2171
Description
Middleware/SessionCookie.php in Slim before 2.6.0 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted session data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
slim/slimPackagist | < 2.6.0 | 2.6.0 |
Affected products
2Patches
Vulnerability mechanics
References
9- www.slimframework.com/2015/03/01/version-260.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-74mf-vjpg-9xh7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-2171ghsaADVISORY
- seclists.org/fulldisclosure/2015/Mar/16nvdWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/slim/slim/CVE-2015-2171.yamlghsaWEB
- github.com/slimphp/Slim/commit/9fa651474eb4d3bb0ce40dd5a55c51bb861c2658ghsaWEB
- github.com/slimphp/Slim/issues/1034nvdWEB
- web.archive.org/web/20200229032229/http://www.securityfocus.com/bid/70087ghsaWEB
- www.securityfocus.com/bid/70087nvd
News mentions
0No linked articles in our index yet.