Smarty CVE-2014-8350 Remote Arbitrary Code Execution Vulnerability
BID:70708
Info
Smarty CVE-2014-8350 Remote Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 70708 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-8350 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2014 12:00AM |
| Updated: | Apr 13 2015 10:01PM |
| Credit: | Thue |
| Vulnerable: |
Smarty Smarty 3.1.20 Smarty Smarty 3.0 rc4 Smarty Smarty 3.0 RC3 Smarty Smarty 3.0 rc2 Smarty Smarty 3.0 RC1 Smarty Smarty 3.0 beta8 Smarty Smarty 3.0 beta7 Smarty Smarty 3.0 beta6 Smarty Smarty 3.0 beta5 Smarty Smarty 3.0 beta4 Smarty Smarty 2.6.24 Smarty Smarty 2.6.22 Smarty Smarty 2.6.20 Smarty Smarty 2.6.18 Smarty Smarty 2.6.17 Smarty Smarty 2.6.16 Smarty Smarty 2.6.15 Smarty Smarty 2.6.14 Smarty Smarty 3.1.9 Smarty Smarty 3.1.8 Smarty Smarty 3.1.7 Smarty Smarty 3.1.6 Smarty Smarty 3.1.5 Smarty Smarty 3.1.4 Smarty Smarty 3.1.3 Smarty Smarty 3.1.2 Smarty Smarty 3.1.11 Smarty Smarty 3.1.10 Smarty Smarty 3.1.1 Smarty Smarty 3.1.0 Smarty Smarty 3.1 Rc1 Smarty Smarty 3.0.7 Smarty Smarty 3.0.6 Smarty Smarty 3.0.5 Smarty Smarty 3.0.4 Smarty Smarty 3.0.3 Smarty Smarty 3.0.2 Smarty Smarty 3.0.1 Smarty Smarty 3.0.0 Smarty Smarty 2.6.9 Smarty Smarty 2.6.7 Smarty Smarty 2.6.6 Smarty Smarty 2.6.5 Smarty Smarty 2.6.4 Smarty Smarty 2.6.3 Smarty Smarty 2.6.26 Smarty Smarty 2.6.25 Smarty Smarty 2.6.2 Smarty Smarty 2.6.13 Smarty Smarty 2.6.12 Smarty Smarty 2.6.11 Smarty Smarty 2.6.10 Smarty Smarty 2.6.1 Smarty Smarty 2.6.0 Rc3 Smarty Smarty 2.6.0 Rc2 Smarty Smarty 2.6.0 Rc1 Smarty Smarty 2.6.0 Smarty Smarty 2.5.0 Rc2 Smarty Smarty 2.5.0 Rc1 Smarty Smarty 2.5.0 Smarty Smarty 2.4.2 Smarty Smarty 2.4.1 Smarty Smarty 2.4.0 Smarty Smarty 2.3.1 Smarty Smarty 2.3.0 Smarty Smarty 2.2.0 Smarty Smarty 2.1.1 Smarty Smarty 2.1.0 Smarty Smarty 2.0.1 Smarty Smarty 2.0.0 Smarty Smarty 1.5.2 Smarty Smarty 1.5.1 Smarty Smarty 1.5.0 Smarty Smarty 1.4.6 Smarty Smarty 1.4.5 Smarty Smarty 1.4.4 Smarty Smarty 1.4.3 Smarty Smarty 1.4.2 Smarty Smarty 1.4.1 Smarty Smarty 1.4.0 B2 Smarty Smarty 1.4.0 B1 Smarty Smarty 1.4.0 Smarty Smarty 1.3.2 Smarty Smarty 1.3.1 Smarty Smarty 1.3.0 Smarty Smarty 1.2.2 Smarty Smarty 1.2.1 Smarty Smarty 1.2.0 Smarty Smarty 1.1.0 Smarty Smarty 1.0b Smarty Smarty 1.0A Smarty Smarty 1.0 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 |
| Not Vulnerable: |
Smarty Smarty 3.1.21 |
Discussion
Smarty CVE-2014-8350 Remote Arbitrary Code Execution Vulnerability
Smarty is prone to a remote arbitrary code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the application.
Versions prior to Smarty 3.1.21 are vulnerable.
Smarty is prone to a remote arbitrary code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the application.
Versions prior to Smarty 3.1.21 are vulnerable.
Exploit / POC
Smarty CVE-2014-8350 Remote Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].