Описание
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 1.20.0-1 |
| esm-infra-legacy/trusty | DNE | |
| precise | DNE | |
| trusty | DNE | |
| trusty/esm | DNE | |
| upstream | released | 1.20.0-1 |
| vivid | released | 1.16.2-1+deb8u1build0.15.04.1 |
| wily | not-affected | 1.20.0-1 |
Показывать по
10
EPSS
Процентиль: 84%
0.02041
Низкий
6.8 Medium
CVSS2
Связанные уязвимости
nvd
больше 10 лет назад
The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary code via the _self variable in a template.
debian
больше 10 лет назад
The displayBlock function Template.php in Sensio Labs Twig before 1.20 ...
EPSS
Процентиль: 84%
0.02041
Низкий
6.8 Medium
CVSS2