|
|
Log in / Subscribe / Register

smarty: PHP code injection

Package(s):smarty CVE #(s):CVE-2008-4810
Created:June 25, 2009 Updated:August 18, 2010
Description: Smarty has a PHP code injection vulnerability. From the National Vulnerability Database entry: The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP code via vectors related to templates and (1) a dollar-sign character, aka "php executed in templates;" and (2) a double quoted literal string, aka a "function injection security hole." NOTE: each vector affects slightly different SVN revisions.
Alerts:
Debian DSA-1919-2 smarty 2010-08-17
Gentoo 201006-13 smarty 2010-06-02
Debian DSA-1919-1 smarty 2009-10-25
Ubuntu USN-791-1 moodle 2009-06-24

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds