Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2012-4437

Опубликовано: 01 окт. 2012
Источник: debian

Описание

Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
smarty3fixed3.1.10-2package
smartyremovedpackage
smartyfixed2.6.26-0.2+squeeze1squeezepackage
smarty3end-of-lifesqueezepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2012/09/19/1

  • http://secunia.com/advisories/50589/

  • http://code.google.com/p/smarty-php/source/browse/trunk/distribution/change_log.txt

  • http://code.google.com/p/smarty-php/source/detail?r=4658

  • https://code.google.com/p/smarty-php/source/detail?r=4660

Связанные уязвимости

ubuntu
больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

nvd
больше 13 лет назад

Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) before 3.1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.

github
больше 3 лет назад

Cross-site Scripting in SmartyException