Перейти к содержимому
Noroxi

Записи smarty

31 опубликованных записей вендора smarty.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
12
С записью об исправлении
87,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

31 записей
  • CVE-2021-26120
    64На этой неделе

    Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

    КритическаяCVSS 9,8Эксплойта нетEPSS 82 %

    smarty · smarty21 февр. 2021 г.

  • CVE-2009-1669
    44В плане

    The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary

    КритическаяCVSS 10,0Proof of conceptEPSS 14 %

    smarty · smarty18 мая 2009 г.

  • CVE-2010-4724
    41В плане

    Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2009-5052
    41В плане

    Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2010-4727
    41В плане

    Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2010-4726
    41В плане

    Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2010-4722
    41В плане

    Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2010-4725
    41В плане

    Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and re

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2017-1000480
    40В плане

    Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not s

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    smarty · smarty3 янв. 2018 г.

  • CVE-2006-7105
    40В плане

    PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    smarty · smarty3 мар. 2007 г.

  • CVE-2011-1028
    39Наблюдать

    The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    smarty · smarty20 нояб. 2019 г.

  • CVE-2010-4723
    37Наблюдать

    Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned obje

    КритическаяCVSS 9,3Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2022-29221
    36Наблюдать

    PHP Code Injection by malicious block or filename in Smarty

    ВысокаяCVSS 8,8Proof of conceptEPSS 5 %

    smarty · smarty24 мая 2022 г.

  • CVE-2021-21408
    36Наблюдать

    Access to restricted PHP code by dynamic static class access in smarty

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    smarty · smarty10 янв. 2022 г.

  • CVE-2021-29454
    36Наблюдать

    Sandbox Escape by math function in smarty

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    smarty · smarty10 янв. 2022 г.

  • CVE-2021-26119
    33Наблюдать

    Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 9 %

    smarty · smarty21 февр. 2021 г.

  • CVE-2018-13982
    31Наблюдать

    Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    smarty · smarty18 сент. 2018 г.

  • CVE-2014-8350
    31Наблюдать

    Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{lite

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    smarty · smarty3 нояб. 2014 г.

  • CVE-2008-4810
    31Наблюдать

    The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrar

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smarty · smarty31 окт. 2008 г.

  • CVE-2009-5053
    31Наблюдать

    Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2008-1066
    31Наблюдать

    The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arb

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smarty · smarty28 февр. 2008 г.

  • CVE-2008-4811
    30Наблюдать

    The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arb

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smarty · smarty31 окт. 2008 г.

  • CVE-2009-5054
    30Наблюдать

    Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass in

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smarty · smarty3 февр. 2011 г.

  • CVE-2005-0913
    30Наблюдать

    Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrar

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    smarty · smarty2 мая 2005 г.

  • CVE-2006-7193
    30Наблюдать

    PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code vi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    smarty · smarty12 апр. 2007 г.