Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
smarty vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2011-3782
phpLD 2-151.2.0 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libs/smarty/Smarty_Compiler.class.php and certain other files.
Phplinkdirectory Phpld 2-151.2.0
5
CVSSv2
CVE-2011-3758
::mound:: 2.1.6 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/smarty/libs/sysplugins/smarty_internal_template.php and certain other files.
Moundlabs \\ \\
9.3
CVSSv2
CVE-2010-4723
Smarty prior to 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.
Smarty Smarty 2.6.1
Smarty Smarty 2.6.17
Smarty Smarty 2.6.6
Smarty Smarty 2.6.16
Smarty Smarty 2.6.20
Smarty Smarty 2.6.12
Smarty Smarty 2.1.1
Smarty Smarty 1.5.0
Smarty Smarty 2.2.0
Smarty Smarty 2.3.1
Smarty Smarty 1.4.4
Smarty Smarty 1.4.0
Smarty Smarty 1.3.0
Smarty Smarty 1.3.2
Smarty Smarty 2.6.26
Smarty Smarty 3.0.0
Smarty Smarty
Smarty Smarty 2.6.7
Smarty Smarty 2.6.9
Smarty Smarty 2.6.3
Smarty Smarty 2.6.4
Smarty Smarty 2.6.0
10
CVSSv2
CVE-2010-4727
Smarty prior to 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.
Smarty Smarty 2.6.22
Smarty Smarty 2.6.10
Smarty Smarty 2.6.3
Smarty Smarty 2.6.5
Smarty Smarty 2.5.0
Smarty Smarty 2.6.0
Smarty Smarty 2.0.0
Smarty Smarty 2.1.0
Smarty Smarty 1.4.6
Smarty Smarty 2.4.2
Smarty Smarty 2.6.18
Smarty Smarty 1.4.3
Smarty Smarty 1.2.2
Smarty Smarty 1.3.1
Smarty Smarty 1.2.1
Smarty Smarty 2.6.25
Smarty Smarty 2.6.17
Smarty Smarty 2.6.15
Smarty Smarty 2.6.16
Smarty Smarty 2.6.13
Smarty Smarty 2.6.14
Smarty Smarty 1.5.0
10
CVSSv2
CVE-2009-5052
Multiple unspecified vulnerabilities in Smarty prior to 3.0.0 beta 6 have unknown impact and attack vectors.
Smarty Smarty 2.6.22
Smarty Smarty 2.6.10
Smarty Smarty 2.6.3
Smarty Smarty 2.6.5
Smarty Smarty 2.5.0
Smarty Smarty 2.6.0
Smarty Smarty 2.1.0
Smarty Smarty 1.4.6
Smarty Smarty 2.4.2
Smarty Smarty 2.3.0
Smarty Smarty 2.6.18
Smarty Smarty 1.4.3
Smarty Smarty 1.2.2
Smarty Smarty 1.3.1
Smarty Smarty 1.2.1
Smarty Smarty 2.6.25
Smarty Smarty 3.0.0
Smarty Smarty 2.6.17
Smarty Smarty 2.6.2
Smarty Smarty 2.6.7
Smarty Smarty 2.6.9
Smarty Smarty 2.6.11
7.5
CVSSv2
CVE-2009-5054
Smarty prior to 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow malicious users to bypass intended access restrictions via standard filesystem operations.
Smarty Smarty 2.6.2
Smarty Smarty 2.6.9
Smarty Smarty 2.6.13
Smarty Smarty 2.6.0
Smarty Smarty 2.0.1
Smarty Smarty 1.5.1
Smarty Smarty 2.4.1
Smarty Smarty 2.4.0
Smarty Smarty 1.0
Smarty Smarty 1.4.0
Smarty Smarty 1.4.1
Smarty Smarty 1.0b
Smarty Smarty 1.2.0
Smarty Smarty 2.6.22
Smarty Smarty 2.6.1
Smarty Smarty 2.6.10
Smarty Smarty 2.6.17
Smarty Smarty 2.5.0
Smarty Smarty 2.6.20
Smarty Smarty 2.6.11
Smarty Smarty 2.2.0
Smarty Smarty 2.3.0
10
CVSSv2
CVE-2010-4722
Unspecified vulnerability in the fetch plugin in Smarty prior to 3.0.2 has unknown impact and remote attack vectors.
Smarty Smarty 2.6.22
Smarty Smarty 2.6.7
Smarty Smarty 2.6.3
Smarty Smarty 2.6.14
Smarty Smarty 2.5.0
Smarty Smarty 2.0.0
Smarty Smarty 2.1.0
Smarty Smarty 1.5.2
Smarty Smarty 2.4.2
Smarty Smarty 1.0a
Smarty Smarty 2.6.18
Smarty Smarty 1.4.0
Smarty Smarty 1.2.2
Smarty Smarty 1.1.0
Smarty Smarty 1.2.1
Smarty Smarty 3.0.0
Smarty Smarty 2.6.1
Smarty Smarty 2.6.10
Smarty Smarty 2.6.17
Smarty Smarty 2.6.2
Smarty Smarty 2.6.0
Smarty Smarty 2.6.20
10
CVSSv2
CVE-2010-4724
Multiple unspecified vulnerabilities in the parser implementation in Smarty prior to 3.0.0 RC3 have unknown impact and remote attack vectors.
Smarty Smarty 2.6.1
Smarty Smarty 2.6.17
Smarty Smarty 2.6.6
Smarty Smarty 2.6.16
Smarty Smarty 2.6.0
Smarty Smarty 2.6.20
Smarty Smarty 2.1.1
Smarty Smarty 1.5.0
Smarty Smarty 2.2.0
Smarty Smarty 2.3.1
Smarty Smarty 1.4.2
Smarty Smarty 1.4.4
Smarty Smarty 1.3.0
Smarty Smarty 1.3.2
Smarty Smarty 2.6.26
Smarty Smarty 3.0.0
Smarty Smarty
Smarty Smarty 2.6.2
Smarty Smarty 2.6.7
Smarty Smarty 2.6.9
Smarty Smarty 2.6.3
Smarty Smarty 2.6.4
10
CVSSv2
CVE-2010-4725
Smarty prior to 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote attack vectors.
Smarty Smarty 2.6.2
Smarty Smarty 2.6.9
Smarty Smarty 2.6.17
Smarty Smarty 2.6.7
Smarty Smarty 2.6.16
Smarty Smarty 2.6.14
Smarty Smarty 2.6.12
Smarty Smarty 2.0.0
Smarty Smarty 1.5.0
Smarty Smarty 1.5.2
Smarty Smarty 2.3.1
Smarty Smarty 1.0a
Smarty Smarty 1.4.0
Smarty Smarty 1.3.2
Smarty Smarty 1.1.0
Smarty Smarty 3.0.0
Smarty Smarty 2.6.15
Smarty Smarty 2.6.13
Smarty Smarty 2.6.0
Smarty Smarty 2.6.11
Smarty Smarty 1.5.1
Smarty Smarty 2.4.1
10
CVSSv2
CVE-2010-4726
Unspecified vulnerability in the math plugin in Smarty prior to 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669.
Smarty Smarty 2.6.1
Smarty Smarty 2.6.17
Smarty Smarty 2.6.6
Smarty Smarty 2.6.16
Smarty Smarty 2.6.0
Smarty Smarty 2.6.20
Smarty Smarty 2.1.1
Smarty Smarty 1.5.0
Smarty Smarty 2.2.0
Smarty Smarty 2.3.1
Smarty Smarty 1.4.2
Smarty Smarty 1.4.4
Smarty Smarty 1.3.0
Smarty Smarty 1.3.2
Smarty Smarty 2.6.26
Smarty Smarty 3.0.0
Smarty Smarty 2.6.13
Smarty Smarty 2.6.14
Smarty Smarty 2.5.0
Smarty Smarty 1.5.1
Smarty Smarty 1.5.2
Smarty Smarty 2.4.1
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48693
CVE-2024-30851
CVE-2024-34460
CVE-2024-2887
local
CVE-2024-27956
remote code execution
CVE-2024-34475
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »