7.5

CVE-2014-8350

Exploit
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Smarty ≫ Smarty Version <= 3.1.20
Smarty ≫ Smarty Version 1.0
Smarty ≫ Smarty Version 1.0a
Smarty ≫ Smarty Version 1.0b
Smarty ≫ Smarty Version 1.1.0
Smarty ≫ Smarty Version 1.2.0
Smarty ≫ Smarty Version 1.2.1
Smarty ≫ Smarty Version 1.2.2
Smarty ≫ Smarty Version 1.3.0
Smarty ≫ Smarty Version 1.3.1
Smarty ≫ Smarty Version 1.3.2
Smarty ≫ Smarty Version 1.4.0
Smarty ≫ Smarty Version 1.4.0 Update b1
Smarty ≫ Smarty Version 1.4.0 Update b2
Smarty ≫ Smarty Version 1.4.1
Smarty ≫ Smarty Version 1.4.2
Smarty ≫ Smarty Version 1.4.3
Smarty ≫ Smarty Version 1.4.4
Smarty ≫ Smarty Version 1.4.5
Smarty ≫ Smarty Version 1.4.6
Smarty ≫ Smarty Version 1.5.0
Smarty ≫ Smarty Version 1.5.1
Smarty ≫ Smarty Version 1.5.2
Smarty ≫ Smarty Version 2.0.0
Smarty ≫ Smarty Version 2.0.1
Smarty ≫ Smarty Version 2.1.0
Smarty ≫ Smarty Version 2.1.1
Smarty ≫ Smarty Version 2.2.0
Smarty ≫ Smarty Version 2.3.0
Smarty ≫ Smarty Version 2.3.1
Smarty ≫ Smarty Version 2.4.0
Smarty ≫ Smarty Version 2.4.1
Smarty ≫ Smarty Version 2.4.2
Smarty ≫ Smarty Version 2.5.0
Smarty ≫ Smarty Version 2.5.0 Update rc1
Smarty ≫ Smarty Version 2.5.0 Update rc2
Smarty ≫ Smarty Version 2.6.0
Smarty ≫ Smarty Version 2.6.0 Update rc1
Smarty ≫ Smarty Version 2.6.0 Update rc2
Smarty ≫ Smarty Version 2.6.0 Update rc3
Smarty ≫ Smarty Version 2.6.1
Smarty ≫ Smarty Version 2.6.2
Smarty ≫ Smarty Version 2.6.3
Smarty ≫ Smarty Version 2.6.4
Smarty ≫ Smarty Version 2.6.5
Smarty ≫ Smarty Version 2.6.6
Smarty ≫ Smarty Version 2.6.7
Smarty ≫ Smarty Version 2.6.9
Smarty ≫ Smarty Version 2.6.10
Smarty ≫ Smarty Version 2.6.11
Smarty ≫ Smarty Version 2.6.12
Smarty ≫ Smarty Version 2.6.13
Smarty ≫ Smarty Version 2.6.14
Smarty ≫ Smarty Version 2.6.15
Smarty ≫ Smarty Version 2.6.16
Smarty ≫ Smarty Version 2.6.17
Smarty ≫ Smarty Version 2.6.18
Smarty ≫ Smarty Version 2.6.20
Smarty ≫ Smarty Version 2.6.22
Smarty ≫ Smarty Version 2.6.24
Smarty ≫ Smarty Version 2.6.25
Smarty ≫ Smarty Version 2.6.26
Smarty ≫ Smarty Version 3.0.0
Smarty ≫ Smarty Version 3.0.0 Update beta4
Smarty ≫ Smarty Version 3.0.0 Update beta5
Smarty ≫ Smarty Version 3.0.0 Update beta6
Smarty ≫ Smarty Version 3.0.0 Update beta7
Smarty ≫ Smarty Version 3.0.0 Update beta8
Smarty ≫ Smarty Version 3.0.0 Update rc1
Smarty ≫ Smarty Version 3.0.0 Update rc2
Smarty ≫ Smarty Version 3.0.0 Update rc3
Smarty ≫ Smarty Version 3.0.0 Update rc4
Smarty ≫ Smarty Version 3.0.1
Smarty ≫ Smarty Version 3.0.2
Smarty ≫ Smarty Version 3.0.3
Smarty ≫ Smarty Version 3.0.4
Smarty ≫ Smarty Version 3.0.5
Smarty ≫ Smarty Version 3.0.6
Smarty ≫ Smarty Version 3.0.7
Smarty ≫ Smarty Version 3.1 Update rc1
Smarty ≫ Smarty Version 3.1.0
Smarty ≫ Smarty Version 3.1.1
Smarty ≫ Smarty Version 3.1.2
Smarty ≫ Smarty Version 3.1.3
Smarty ≫ Smarty Version 3.1.4
Smarty ≫ Smarty Version 3.1.5
Smarty ≫ Smarty Version 3.1.6
Smarty ≫ Smarty Version 3.1.7
Smarty ≫ Smarty Version 3.1.8
Smarty ≫ Smarty Version 3.1.9
Smarty ≫ Smarty Version 3.1.10
Smarty ≫ Smarty Version 3.1.11
Smarty ≫ Smarty Version 3.1.12
Smarty ≫ Smarty Version 3.1.13
Smarty ≫ Smarty Version 3.1.14
Smarty ≫ Smarty Version 3.1.15
Smarty ≫ Smarty Version 3.1.16
Smarty ≫ Smarty Version 3.1.17
Smarty ≫ Smarty Version 3.1.18
Smarty ≫ Smarty Version 3.1.19
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.13% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://advisories.mageia.org/MGASA-2014-0468.html
http://www.mandriva.com/security/advisories?name=MDVSA-2014:221
http://seclists.org/oss-sec/2014/q4/420
Exploit
http://seclists.org/oss-sec/2014/q4/421
Exploit
http://www.securityfocus.com/bid/70708
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765920
Exploit
https://code.google.com/p/smarty-php/source/browse/trunk/distribution/change_log.txt?r=4902
https://exchange.xforce.ibmcloud.com/vulnerabilities/97725