Smarty PHP fixes a cache-dependent route to remote code execution
Smarty PHP releases before 4.5.8 and 5.8.5 can escalate a template injection issue from cross-site scripting to remote code execution under specific conditions. The attacker must control an unescaped rendered value. The template must use {extends}, and rendered-template caching must be enabled. The cache option is disabled by default. Updating to a fixed release removes the issue.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.