CVE Vulnerabilities

CVE-2008-4811

Published: Oct 31, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a (backslash) before a dollar-sign character.

Affected Software

NameVendorStart VersionEnd Version
SmartySmarty*2.6.20 (including)
SmartySmarty1.0 (including)1.0 (including)
SmartySmarty1.0a (including)1.0a (including)
SmartySmarty1.0b (including)1.0b (including)
SmartySmarty1.1.0 (including)1.1.0 (including)
SmartySmarty1.2.0 (including)1.2.0 (including)
SmartySmarty1.2.1 (including)1.2.1 (including)
SmartySmarty1.2.2 (including)1.2.2 (including)
SmartySmarty1.3.0 (including)1.3.0 (including)
SmartySmarty1.3.1 (including)1.3.1 (including)
SmartySmarty1.3.2 (including)1.3.2 (including)
SmartySmarty1.4.0 (including)1.4.0 (including)
SmartySmarty1.4.0-b1 (including)1.4.0-b1 (including)
SmartySmarty1.4.0-b2 (including)1.4.0-b2 (including)
SmartySmarty1.4.1 (including)1.4.1 (including)
SmartySmarty1.4.2 (including)1.4.2 (including)
SmartySmarty1.4.3 (including)1.4.3 (including)
SmartySmarty1.4.4 (including)1.4.4 (including)
SmartySmarty1.4.5 (including)1.4.5 (including)
SmartySmarty1.4.6 (including)1.4.6 (including)
SmartySmarty1.5.0 (including)1.5.0 (including)
SmartySmarty1.5.1 (including)1.5.1 (including)
SmartySmarty1.5.2 (including)1.5.2 (including)
SmartySmarty2.0.0 (including)2.0.0 (including)
SmartySmarty2.0.1 (including)2.0.1 (including)
SmartySmarty2.1.0 (including)2.1.0 (including)
SmartySmarty2.1.1 (including)2.1.1 (including)
SmartySmarty2.2.0 (including)2.2.0 (including)
SmartySmarty2.3.0 (including)2.3.0 (including)
SmartySmarty2.3.1 (including)2.3.1 (including)
SmartySmarty2.4.0 (including)2.4.0 (including)
SmartySmarty2.4.1 (including)2.4.1 (including)
SmartySmarty2.4.2 (including)2.4.2 (including)
SmartySmarty2.5.0 (including)2.5.0 (including)
SmartySmarty2.5.0-rc1 (including)2.5.0-rc1 (including)
SmartySmarty2.5.0-rc2 (including)2.5.0-rc2 (including)
SmartySmarty2.6.0 (including)2.6.0 (including)
SmartySmarty2.6.0-rc1 (including)2.6.0-rc1 (including)
SmartySmarty2.6.0-rc2 (including)2.6.0-rc2 (including)
SmartySmarty2.6.0-rc3 (including)2.6.0-rc3 (including)
SmartySmarty2.6.1 (including)2.6.1 (including)
SmartySmarty2.6.2 (including)2.6.2 (including)
SmartySmarty2.6.3 (including)2.6.3 (including)
SmartySmarty2.6.4 (including)2.6.4 (including)
SmartySmarty2.6.5 (including)2.6.5 (including)
SmartySmarty2.6.6 (including)2.6.6 (including)
SmartySmarty2.6.7 (including)2.6.7 (including)
SmartySmarty2.6.9 (including)2.6.9 (including)
SmartySmarty2.6.10 (including)2.6.10 (including)
SmartySmarty2.6.11 (including)2.6.11 (including)
SmartySmarty2.6.12 (including)2.6.12 (including)
SmartySmarty2.6.13 (including)2.6.13 (including)
SmartySmarty2.6.14 (including)2.6.14 (including)
SmartySmarty2.6.15 (including)2.6.15 (including)
SmartySmarty2.6.16 (including)2.6.16 (including)
SmartySmarty2.6.17 (including)2.6.17 (including)
SmartySmarty2.6.18 (including)2.6.18 (including)
Gallery2Ubuntudapper*
Gallery2Ubuntuhardy*
MoodleUbuntudapper*
MoodleUbuntuhardy*
MoodleUbuntuintrepid*
SmartyUbuntudapper*
SmartyUbuntugutsy*
SmartyUbuntuhardy*
SmartyUbuntuintrepid*

References