Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
smarty vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2018-20566
An issue exists in DouCo DouPHP 1.5 20181221. It allows full path disclosure in "Smarty error: unable to read resource" error messages for a crafted installation page.
Douco Douphp 1.5
5
CVSSv2
CVE-2018-13982
Smarty_Security::isTrustedResourceDir() in Smarty prior to 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the executed template code to bypass the trusted directory security restriction and read ...
Smarty Smarty
Debian Debian Linux 9.0
5
CVSSv2
CVE-2011-3782
phpLD 2-151.2.0 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by libs/smarty/Smarty_Compiler.class.php and certain other files.
Phplinkdirectory Phpld 2-151.2.0
5
CVSSv2
CVE-2011-3758
::mound:: 2.1.6 allows remote malicious users to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/smarty/libs/sysplugins/smarty_internal_template.php and certain other files.
Moundlabs \\ \\
5
CVSSv2
CVE-2007-3171
Uebimiau Webmail allows remote malicious users to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages.
Uebimiau Uebimiau 2.7.10
Uebimiau Uebimiau 2.7.2
Uebimiau Uebimiau 2.7.9
1 EDB exploit
4.6
CVSSv2
CVE-2017-1000454
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read prior to 2.2, and local file inclusion since 2.2.1
Cmsmadesimple Cms Made Simple
4.3
CVSSv2
CVE-2014-8939
Lexiglot through 2014-11-20 allows remote malicious users to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages.
Piwigo Lexiglot
4.3
CVSSv2
CVE-2017-9332
The smarty_self function in modules/module_smarty.php in PivotX 2.3.11 mishandles the URI, allowing XSS via vectors involving quotes in the self Smarty tag.
Pivotx Pivotx 2.3.11
4.3
CVSSv2
CVE-2012-4437
Cross-site scripting (XSS) vulnerability in the SmartyException class in Smarty (aka smarty-php) prior to 3.1.12 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors that trigger a Smarty exception.
Smarty Smarty 2.6.10
Smarty Smarty 2.6.17
Smarty Smarty 2.6.7
Smarty Smarty 3.1.1
Smarty Smarty 2.6.13
Smarty Smarty 2.6.0
Smarty Smarty 2.6.11
Smarty Smarty 1.5.1
Smarty Smarty 2.4.1
Smarty Smarty 2.4.0
Smarty Smarty 2.6.25
Smarty Smarty 1.0
Smarty Smarty 3.1.8
Smarty Smarty 2.6.18
Smarty Smarty 3.0.0
Smarty Smarty 1.4.3
Smarty Smarty 1.4.4
Smarty Smarty 3.0.1
Smarty Smarty 1.1.0
Smarty Smarty 1.2.1
Smarty Smarty 3.1.3
Smarty Smarty 3.1.2
4.3
CVSSv2
CVE-2012-4277
Cross-site scripting (XSS) vulnerability in the smarty_function_html_options_optoutput function in distribution/libs/plugins/function.html_options.php in Smarty prior to 3.1.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Smarty Smarty
Smarty Smarty 3.1.0
Smarty Smarty 3.0.4
Smarty Smarty 3.0.5
Smarty Smarty 3.0.6
Smarty Smarty 3.0.0
Smarty Smarty 3.0.1
Smarty Smarty 2.6.9
Smarty Smarty 2.6.4
Smarty Smarty 2.6.13
Smarty Smarty 2.6.0
Smarty Smarty 2.0.1
Smarty Smarty 2.2.0
Smarty Smarty 2.3.1
Smarty Smarty 2.6.18
Smarty Smarty 1.5.0
Smarty Smarty 1.5.2
Smarty Smarty 1.4.4
Smarty Smarty 1.4.0
Smarty Smarty 1.3.2
Smarty Smarty 1.1.0
Smarty Smarty 3.1.5
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »