CVE-2017-1000480
03.01.2018, 18:29
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.
| Vendor | Product | Version |
|---|---|---|
| smarty | smarty | 3.0.0 ≤ 𝑥 < 3.1.32 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| smarty3 |
|
References