Symfony Pentest

Pentest Symfony applications - fingerprint versions, test for known CVEs (CVE-2019-18889, CVE-2025-64500, CVE-2024-51736, CVE-2025-47946, CVE-2026-24739), exploit APP_SECRET disclosure via _fragment, test PATH_INFO bypass, check for exposed .env files, debug routes, and common misconfigurations. Use this skill whenever the user mentions Symfony, PHP frameworks, web application security testing, or needs to assess a Symfony-based application (Drupal, Shopware, Ibexa, OroCRM all embed Symfony components).

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/network-services-pentesting/pentesting-web/symphony commit 1743071449

Frequently asked questions

npx skillmds@latest add abelrguezr/symfony-pentest