LWN.net Logo

smarty: remote code execution

Package(s):smarty CVE #(s):
Created:March 30, 2005 Updated:April 11, 2005
Description: The "template security" feature in smarty can be bypassed, enabling the execution of arbitrary PHP code by a remote attacker. Version 2.6.8 fixes the problem.
Alerts:
Gentoo 200503-35:02 2005-03-30
Gentoo 200503-35 2005-03-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds