Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-21424 — El WebProfiler de Symfony expone rutas internas del servidor si no está deshabilitado en producción | Kitploit
Tools/GitHubGitHub/moften/cve-2021-21424
Vulnerability AnalysisExploitationInformation GatheringWeb SecurityPenetration TestingMisconfiguration
GitHubmoften/cve-2021-21424

CVE-2021-21424

El WebProfiler de Symfony expone rutas internas del servidor si no está deshabilitado en producción

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-21424

Directory Traversal and file exposure • CVE-2021-21424 • Description: WebProfiler exposes internal server paths if it is not disabled in production. • Affected versions: Symfony 2.8 to 5.x. • Typical bypass: direct access to /app_dev.php/_profiler/.

root@kitploit:~
Summary of CVE-2021-21424
•	CVE: 2021-21424
•	Component: Web Profiler / Dev Toolbar
•	Impact: Exposure of sensitive information (environment, paths, parameters)
•	Requirement: That /app_dev.php, /_profiler or /_wdt are accessible from production.
•	Risk: Allows privilege escalation, access to environment variables, credentials, internal paths, request debugging and controller profiling.
Download Tool