7.5
CVSSv2

CVE-2009-5054

Published: 03/02/2011 Updated: 15/02/2011
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Smarty prior to 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow malicious users to bypass intended access restrictions via standard filesystem operations.

Vulnerable Product Search on Vulmon Subscribe to Product

smarty smarty 2.6.2

smarty smarty 2.6.9

smarty smarty 2.6.13

smarty smarty 2.6.0

smarty smarty 2.0.1

smarty smarty 1.5.1

smarty smarty 2.4.1

smarty smarty 2.4.0

smarty smarty 1.0

smarty smarty 1.4.0

smarty smarty 1.4.1

smarty smarty 1.0b

smarty smarty 1.2.0

smarty smarty 2.6.22

smarty smarty 2.6.1

smarty smarty 2.6.10

smarty smarty 2.6.17

smarty smarty 2.5.0

smarty smarty 2.6.20

smarty smarty 2.6.11

smarty smarty 2.2.0

smarty smarty 2.3.0

smarty smarty 1.2.2

smarty smarty 1.3.0

smarty smarty 1.3.1

smarty smarty 1.3.2

smarty smarty 2.6.4

smarty smarty 2.6.5

smarty smarty 2.6.6

smarty smarty 2.6.15

smarty smarty 2.1.0

smarty smarty 2.1.1

smarty smarty 1.4.6

smarty smarty 1.5.0

smarty smarty 2.6.18

smarty smarty 1.4.2

smarty smarty 1.4.3

smarty smarty 1.4.4

smarty smarty 1.4.5

smarty smarty 2.6.24

smarty smarty 2.6.25

smarty smarty

smarty smarty 2.6.7

smarty smarty 2.6.3

smarty smarty 2.6.16

smarty smarty 2.6.14

smarty smarty 2.6.12

smarty smarty 2.0.0

smarty smarty 1.5.2

smarty smarty 2.4.2

smarty smarty 2.3.1

smarty smarty 1.0a

smarty smarty 1.1.0

smarty smarty 1.2.1