|
|
Log in / Subscribe / Register

php-Smarty: remote code execution

Package(s):php-Smarty CVE #(s):CVE-2008-4811
Created:November 7, 2008 Updated:June 3, 2010
Description: From the CVE entry: The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a \ (backslash) before a dollar-sign character.
Alerts:
Gentoo 201006-13 smarty 2010-06-02
Ubuntu USN-791-1 moodle 2009-06-24
Mandriva MDVSA-2009:052 php-smarty 2009-02-24
Debian DSA-1691-1 moodle 2008-12-22
Fedora FEDORA-2008-10409 php-Smarty 2008-11-26
Fedora FEDORA-2008-9420 php-Smarty 2008-11-07
Fedora FEDORA-2008-9401 php-Smarty 2008-11-07

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds