7.5

CVE-2009-5054

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.

Data is provided by the National Vulnerability Database (NVD)
SmartySmarty Version <= 2.6.26
SmartySmarty Version1.0
SmartySmarty Version1.0a
SmartySmarty Version1.0b
SmartySmarty Version1.1.0
SmartySmarty Version1.2.0
SmartySmarty Version1.2.1
SmartySmarty Version1.2.2
SmartySmarty Version1.3.0
SmartySmarty Version1.3.1
SmartySmarty Version1.3.2
SmartySmarty Version1.4.0
SmartySmarty Version1.4.0 Updateb1
SmartySmarty Version1.4.0 Updateb2
SmartySmarty Version1.4.1
SmartySmarty Version1.4.2
SmartySmarty Version1.4.3
SmartySmarty Version1.4.4
SmartySmarty Version1.4.5
SmartySmarty Version1.4.6
SmartySmarty Version1.5.0
SmartySmarty Version1.5.1
SmartySmarty Version1.5.2
SmartySmarty Version2.0.0
SmartySmarty Version2.0.1
SmartySmarty Version2.1.0
SmartySmarty Version2.1.1
SmartySmarty Version2.2.0
SmartySmarty Version2.3.0
SmartySmarty Version2.3.1
SmartySmarty Version2.4.0
SmartySmarty Version2.4.1
SmartySmarty Version2.4.2
SmartySmarty Version2.5.0
SmartySmarty Version2.5.0 Updaterc1
SmartySmarty Version2.5.0 Updaterc2
SmartySmarty Version2.6.0
SmartySmarty Version2.6.0 Updaterc1
SmartySmarty Version2.6.0 Updaterc2
SmartySmarty Version2.6.0 Updaterc3
SmartySmarty Version2.6.1
SmartySmarty Version2.6.2
SmartySmarty Version2.6.3
SmartySmarty Version2.6.4
SmartySmarty Version2.6.5
SmartySmarty Version2.6.6
SmartySmarty Version2.6.7
SmartySmarty Version2.6.9
SmartySmarty Version2.6.10
SmartySmarty Version2.6.11
SmartySmarty Version2.6.12
SmartySmarty Version2.6.13
SmartySmarty Version2.6.14
SmartySmarty Version2.6.15
SmartySmarty Version2.6.16
SmartySmarty Version2.6.17
SmartySmarty Version2.6.18
SmartySmarty Version2.6.20
SmartySmarty Version2.6.22
SmartySmarty Version2.6.24
SmartySmarty Version2.6.25
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.201
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P