Записи smarty
31 опубликованных записей вендора smarty.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 87,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')6
- CWE-20 Improper Input Validation5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
31 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2021-26120Эксплойта нет | Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.smarty · smarty · CWE-94 | Критическая9,8 | — | 82,3 % | 21 февр. 2021 г. |
44В плане | CVE-2009-1669Proof of concept | The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrarysmarty · smarty · CWE-20 | Критическая10,0 | — | 14,1 % | 18 мая 2009 г. |
41В плане | CVE-2010-4724Эксплойта нет | Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.smarty · smarty | Критическая10,0 | — | 1,9 % | 3 февр. 2011 г. |
41В плане | CVE-2009-5052Эксплойта нет | Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.smarty · smarty | Критическая10,0 | — | 1,9 % | 3 февр. 2011 г. |
41В плане | CVE-2010-4727Эксплойта нет | Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.smarty · smarty · CWE-20 | Критическая10,0 | — | 1,9 % | 3 февр. 2011 г. |
41В плане | CVE-2010-4726Эксплойта нет | Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors.smarty · smarty | Критическая10,0 | — | 1,9 % | 3 февр. 2011 г. |
41В плане | CVE-2010-4722Эксплойта нет | Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.smarty · smarty | Критическая10,0 | — | 1,9 % | 3 февр. 2011 г. |
41В плане | CVE-2010-4725Эксплойта нет | Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and resmarty · smarty | Критическая10,0 | — | 1,9 % | 3 февр. 2011 г. |
40В плане | CVE-2017-1000480Эксплойта нет | Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not ssmarty · smarty · CWE-94 | Критическая9,8 | — | 3,1 % | 3 янв. 2018 г. |
40В плане | CVE-2006-7105Эксплойта нет | PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via asmarty · smarty · CWE-94 | Критическая9,8 | — | 1,8 % | 3 мар. 2007 г. |
39Наблюдать | CVE-2011-1028Эксплойта нет | The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_smarty · smarty · CWE-20 | Критическая9,8 | — | 1,6 % | 20 нояб. 2019 г. |
37Наблюдать | CVE-2010-4723Эксплойта нет | Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned objesmarty · smarty · CWE-264 | Критическая9,3 | — | 1,7 % | 3 февр. 2011 г. |
36Наблюдать | CVE-2022-29221Proof of concept | PHP Code Injection by malicious block or filename in Smartysmarty · smarty · CWE-94 | Высокая8,8 | — | 4,9 % | 24 мая 2022 г. |
36Наблюдать | CVE-2021-21408Эксплойта нет | Access to restricted PHP code by dynamic static class access in smartysmarty · smarty · CWE-20 | Высокая8,8 | — | 2,2 % | 10 янв. 2022 г. |
36Наблюдать | CVE-2021-29454Эксплойта нет | Sandbox Escape by math function in smartysmarty · smarty · CWE-74 | Высокая8,8 | — | 1,9 % | 10 янв. 2022 г. |
33Наблюдать | CVE-2021-26119Эксплойта нет | Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.smarty · smarty | Высокая7,5 | — | 9,4 % | 21 февр. 2021 г. |
31Наблюдать | CVE-2018-13982Эксплойта нет | Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template codesmarty · smarty · CWE-22 | Высокая7,5 | — | 3,5 % | 18 сент. 2018 г. |
31Наблюдать | CVE-2014-8350Эксплойта нет | Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{litesmarty · smarty · CWE-94 | Высокая7,5 | — | 3,1 % | 3 нояб. 2014 г. |
31Наблюдать | CVE-2008-4810Эксплойта нет | The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrarsmarty · smarty · CWE-94 | Высокая7,5 | — | 2,2 % | 31 окт. 2008 г. |
31Наблюдать | CVE-2009-5053Эксплойта нет | Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a smarty · smarty | Высокая7,5 | — | 2,1 % | 3 февр. 2011 г. |
31Наблюдать | CVE-2008-1066Эксплойта нет | The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbsmarty · smarty · CWE-20 | Высокая7,5 | — | 2,0 % | 28 февр. 2008 г. |
30Наблюдать | CVE-2008-4811Эксплойта нет | The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbsmarty · smarty · CWE-264 | Высокая7,5 | — | 1,6 % | 31 окт. 2008 г. |
30Наблюдать | CVE-2009-5054Эксплойта нет | Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass insmarty · smarty · CWE-264 | Высокая7,5 | — | 1,6 % | 3 февр. 2011 г. |
30Наблюдать | CVE-2005-0913Эксплойта нет | Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrarsmarty · smarty | Высокая7,5 | — | 1,5 % | 2 мая 2005 г. |
30Наблюдать | CVE-2006-7193Эксплойта нет | PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code vismarty · smarty | Высокая7,5 | — | 1,5 % | 12 апр. 2007 г. |
- CVE-2021-2612064На этой неделе
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
КритическаяCVSS 9,8Эксплойта нетEPSS 82 %smarty · smarty21 февр. 2021 г.
- CVE-2009-166944В плане
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary
КритическаяCVSS 10,0Proof of conceptEPSS 14 %smarty · smarty18 мая 2009 г.
- CVE-2010-472441В плане
Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2009-505241В плане
Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2010-472741В плане
Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2010-472641В плане
Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2010-472241В плане
Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2010-472541В плане
Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and re
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2017-100048040В плане
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not s
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %smarty · smarty3 янв. 2018 г.
- CVE-2006-710540В плане
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %smarty · smarty3 мар. 2007 г.
- CVE-2011-102839Наблюдать
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %smarty · smarty20 нояб. 2019 г.
- CVE-2010-472337Наблюдать
Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned obje
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2022-2922136Наблюдать
PHP Code Injection by malicious block or filename in Smarty
ВысокаяCVSS 8,8Proof of conceptEPSS 5 %smarty · smarty24 мая 2022 г.
- CVE-2021-2140836Наблюдать
Access to restricted PHP code by dynamic static class access in smarty
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %smarty · smarty10 янв. 2022 г.
- CVE-2021-2945436Наблюдать
Sandbox Escape by math function in smarty
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %smarty · smarty10 янв. 2022 г.
- CVE-2021-2611933Наблюдать
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %smarty · smarty21 февр. 2021 г.
- CVE-2018-1398231Наблюдать
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %smarty · smarty18 сент. 2018 г.
- CVE-2014-835031Наблюдать
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{lite
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %smarty · smarty3 нояб. 2014 г.
- CVE-2008-481031Наблюдать
The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrar
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %smarty · smarty31 окт. 2008 г.
- CVE-2009-505331Наблюдать
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2008-106631Наблюдать
The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arb
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %smarty · smarty28 февр. 2008 г.
- CVE-2008-481130Наблюдать
The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arb
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %smarty · smarty31 окт. 2008 г.
- CVE-2009-505430Наблюдать
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass in
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %smarty · smarty3 февр. 2011 г.
- CVE-2005-091330Наблюдать
Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrar
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %smarty · smarty2 мая 2005 г.
- CVE-2006-719330Наблюдать
PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %smarty · smarty12 апр. 2007 г.