Логотип exploitDog
bind:CVE-2024-35226
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-35226

Количество 6

Количество 6

ubuntu логотип

CVE-2024-35226

около 1 года назад

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2024-35226

около 1 года назад

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2024-35226

около 1 года назад

Smarty is a template engine for PHP, facilitating the separation of pr ...

CVSS3: 7.3
EPSS: Низкий
redos логотип

ROS-20250212-09

4 месяца назад

Уязвимость postfixadmin

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4rmg-292m-wg3w

около 1 года назад

Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag

CVSS3: 7.3
EPSS: Низкий
fstec логотип

BDU:2025-03330

около 1 года назад

Уязвимость шаблонизатора для PHP Smarty, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный PHP-код

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-35226

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

CVSS3: 7.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-35226

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.

CVSS3: 7.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-35226

Smarty is a template engine for PHP, facilitating the separation of pr ...

CVSS3: 7.3
0%
Низкий
около 1 года назад
redos логотип
ROS-20250212-09

Уязвимость postfixadmin

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4rmg-292m-wg3w

Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag

CVSS3: 7.3
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-03330

Уязвимость шаблонизатора для PHP Smarty, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный PHP-код

CVSS3: 7.3
0%
Низкий
около 1 года назад

Уязвимостей на страницу