Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Smarty MEDIUM 5.9
CVE-2018-16831

Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.

Fix: after 3.1.32
Fix from $1,600 2018-09-11
Smarty CRITICAL 9.8
CVE-2017-1000480

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize t…

Fix: 3.1.32+
Fix from $2,300 2018-01-03
Smarty HIGH 7.5
CVE-2014-8350

Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/li…

Fix: after 3.1.20
Fix from $1,950 2014-11-03
Smarty HIGH 10.0
CVE-2010-4725

Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote atta…

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 10.0
CVE-2010-4726

Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2…

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 10.0
CVE-2010-4727

Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 10.0
CVE-2009-5052

Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 10.0
CVE-2010-4722

Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.

Fix: after 3.0.1
Fix from $1,950 2011-02-03
Smarty HIGH 10.0
CVE-2010-4724

Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 9.3
CVE-2010-4723

Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which…

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 7.5
CVE-2009-5053

Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache fil…

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Smarty HIGH 7.5
CVE-2009-5054

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended ac…

Fix: after 2.6.26
Fix from $1,950 2011-02-03
Smarty HIGH 10.0
CVE-2009-1669EPSS 14%

The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands…

No fix yet
Fix from $1,950 2009-05-18
Smarty HIGH 7.5
CVE-2008-4810

The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP cod…

Mitigation only
Fix from $1,950 2008-10-31
Smarty HIGH 7.5
CVE-2008-4811

The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PH…

Mitigation only
Fix from $1,950 2008-10-31
Smarty HIGH 7.5
CVE-2008-1066

The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PH…

Fix: after 2.6.18
Fix from $1,950 2008-02-28
Smarty HIGH 7.5
CVE-2006-7193

PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2007-04-12
Smarty CRITICAL 9.8
CVE-2006-7105

PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in t…

No fix yet
Fix from $2,300 2007-03-03
Smarty HIGH 7.5
CVE-2005-0913

Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP cod…

Patch available
Fix from $1,950 2005-05-02