7.5
CVSSv2

CVE-2014-8350

Published: 03/11/2014 Updated: 08/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Smarty prior to 3.1.21 allows remote malicious users to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

smarty smarty 3.1.16

smarty smarty 3.1.15

smarty smarty 3.1.6

smarty smarty 3.1.5

smarty smarty 3.1.19

smarty smarty 3.1.18

smarty smarty 3.1.17

smarty smarty 3.1.8

smarty smarty 3.1.7

smarty smarty 3.1.10

smarty smarty 3.1.1

smarty smarty 3.0.2

smarty smarty 3.0.1

smarty smarty 3.0.0

smarty smarty 2.6.4

smarty smarty 2.6.3

smarty smarty 2.6.17

smarty smarty 2.6.16

smarty smarty 2.6.1

smarty smarty 2.6.0

smarty smarty 2.4.2

smarty smarty 2.4.1

smarty smarty 2.0.0

smarty smarty 1.5.2

smarty smarty 1.4.2

smarty smarty 1.4.1

smarty smarty 1.2.2

smarty smarty 1.2.1

smarty smarty

smarty smarty 3.1.12

smarty smarty 3.1.9

smarty smarty 3.1.2

smarty smarty 3.1.11

smarty smarty 3.0.5

smarty smarty 3.0.4

smarty smarty 3.0.3

smarty smarty 2.6.6

smarty smarty 2.6.5

smarty smarty 2.6.2

smarty smarty 2.6.18

smarty smarty 2.6.11

smarty smarty 2.6.10

smarty smarty 2.5.0

smarty smarty 2.1.0

smarty smarty 2.0.1

smarty smarty 1.4.4

smarty smarty 1.4.3

smarty smarty 1.3.1

smarty smarty 1.3.0

smarty smarty 3.1.0

smarty smarty 3.1

smarty smarty 2.6.26

smarty smarty 2.6.25

smarty smarty 2.6.15

smarty smarty 2.6.14

smarty smarty 2.4.0

smarty smarty 2.3.1

smarty smarty 1.5.1

smarty smarty 1.5.0

smarty smarty 1.4.0

smarty smarty 1.2.0

smarty smarty 1.1.0

smarty smarty 1.0b

smarty smarty 3.1.14

smarty smarty 3.1.13

smarty smarty 3.1.4

smarty smarty 3.1.3

smarty smarty 3.0.7

smarty smarty 3.0.6

smarty smarty 2.6.9

smarty smarty 2.6.7

smarty smarty 2.6.24

smarty smarty 2.6.22

smarty smarty 2.6.20

smarty smarty 2.6.13

smarty smarty 2.6.12

smarty smarty 2.3.0

smarty smarty 2.2.0

smarty smarty 2.1.1

smarty smarty 1.4.6

smarty smarty 1.4.5

smarty smarty 1.3.2

smarty smarty 1.0a

smarty smarty 1.0

Vendor Advisories

Debian Bug report logs - #765920 smarty3: CVE-2014-8350: secure mode bypass Package: smarty3; Maintainer for smarty3 is Mike Gabriel &lt;sunweaver@debianorg&gt;; Source for smarty3 is src:smarty3 (PTS, buildd, popcon) Reported by: Thue &lt;thuejk@gmailcom&gt; Date: Sun, 19 Oct 2014 09:18:11 UTC Severity: important Tags: fixed ...