Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000480

Опубликовано: 03 янв. 2018
Источник: debian
EPSS Низкий

Описание

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
smartyremovedpackage
smarty3fixed3.1.31+20161214.1.c7d42e4+selfpack1-3package

Примечания

  • https://github.com/smarty-php/smarty/commit/614ad1f8b9b00086efc123e49b7bb8efbfa81b61

EPSS

Процентиль: 87%
0.03124
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

CVSS3: 9.8
nvd
больше 8 лет назад

Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.

CVSS3: 9.8
github
больше 4 лет назад

Smarty PHP code injection

EPSS

Процентиль: 87%
0.03124
Низкий
Уязвимость CVE-2017-1000480