[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1919 smarty -- several vulnerabilities

ID: oval:org.mitre.oval:def:7911Date: (C)2009-12-15   (M)2017-10-04
Class: PATCHFamily: unix




Several remote vulnerabilities have been discovered in Smarty, a PHP templating engine. The Common Vulnerabilities and Exposures project identifies the following problems: The _expand_quoted_text function allows for certain restrictions in templates, like function calling and PHP execution, to be bypassed. The smarty_function_math function allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function.

Platform:
Debian 5.0
Debian 4.0
Product:
smarty
Reference:
DSA-1919
CVE-2008-4810
CVE-2009-1669
CVE    2
CVE-2008-4810
CVE-2009-1669
CPE    2
cpe:/o:debian:debian_linux:5.0
cpe:/o:debian:debian_linux:4.0

© 2013 SecPod Technologies