** DISPUTED ** PHP remote file inclusion vulnerability...
High severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 17, 2025
Description
Published by the National Vulnerability Database
Mar 3, 2007
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 17, 2025
** DISPUTED ** PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect.
References