[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-13982 -- smarty3

ID: oval:org.secpod.oval:def:2001369Date: (C)2019-05-30   (M)2023-07-25
Class: VULNERABILITYFamily: unix




Smarty_Security::isTrustedResourceDir in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read arbitrary files.

Platform:
Debian 9.x
Product:
smarty3
Reference:
CVE-2018-13982
CVE    1
CVE-2018-13982
CPE    2
cpe:/o:debian:debian_linux:9.x
cpe:/a:smarty:smarty3

© SecPod Technologies