php-Smarty: remote code execution
| Package(s): | php-Smarty | CVE #(s): | CVE-2008-4811 | ||||||||||||||||||||||||||||
| Created: | November 7, 2008 | Updated: | June 3, 2010 | ||||||||||||||||||||||||||||
| Description: | From the CVE entry: The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a \ (backslash) before a dollar-sign character. | ||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||
