[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1919 smarty -- several vulnerabilities

ID: oval:org.mitre.oval:def:7911Date: (C)2009-12-15   (M)2021-06-02
Class: PATCHFamily: unix




Several remote vulnerabilities have been discovered in Smarty, a PHP templating engine. The Common Vulnerabilities and Exposures project identifies the following problems: The _expand_quoted_text function allows for certain restrictions in templates, like function calling and PHP execution, to be bypassed. The smarty_function_math function allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function.

Platform:
Debian 5.0
Debian 4.0
Product:
smarty
Reference:
DSA-1919
CVE-2008-4810
CVE-2009-1669
CVE    2
CVE-2008-4810
CVE-2009-1669
CPE    2
cpe:/o:debian:debian_linux:4.0
cpe:/o:debian:debian_linux:5.0

© SecPod Technologies