|
|
| |
|
| |
php-smarty: arbitrary command execution
| Package(s): | php-Smarty |
CVE #(s): | CVE-2009-1669
|
| Created: | May 28, 2009 |
Updated: | August 18, 2010 |
| Description: |
php-smarty has an arbitrary command execution vulnerability.
From the
Red Hat bug entry:
The smarty_function_math function in libs/plugins/function.math.php in
Smarty 2.6.22 allows context-dependent attackers to execute arbitrary
commands via shell metacharacters in the equation attribute of the
math function. NOTE: some of these details are obtained from third
party information. |
| Alerts: |
|
( Log in to post comments)
|
|
|