[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5151-1 smarty3 -- smarty3

ID: oval:org.secpod.oval:def:88359Date: (C)2023-03-28   (M)2023-11-13
Class: PATCHFamily: unix




Several security vulnerabilities have been discovered in smarty3, the compiling PHP template engine. Template authors are able to run restricted static php methods or even arbitrary PHP code by crafting a malicious math string or by choosing an invalid {block} or {include} file name. If a math string was passed through as user provided data to the math function, remote users were able to run arbitrary PHP code as well.

Platform:
Linux Mint 4
Linux Mint 5
Product:
smarty3
Reference:
DSA-5151-1
CVE-2021-21408
CVE-2021-26119
CVE-2021-26120
CVE-2021-29454
CVE-2022-29221
CVE    5
CVE-2021-21408
CVE-2021-26119
CVE-2021-26120
CVE-2021-29454
...
CPE    3
cpe:/o:linux_mint:linux_mint:4
cpe:/a:smarty:smarty3
cpe:/o:linux_mint:linux_mint:5

© SecPod Technologies