CVE-2011-1028
20.11.2019, 15:15
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.Enginsight
Vendor | Product | Version |
---|---|---|
smarty | smarty | 3.0.0 ≤ 𝑥 < 3.0.7 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
gallery2 |
| ||||||||||||||||||||||||||||||||
moodle |
| ||||||||||||||||||||||||||||||||
smarty |
|
Common Weakness Enumeration
References