CVE-2018-16831
11.09.2018, 13:29
Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.
Vendor | Product | Version |
---|---|---|
smarty | smarty | 3.0.0 ≤ 𝑥 ≤ 3.1.32 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases