CVE-2005-0913: High severity Smarty smarty vulnerability
Published Mar 29, 2005
·Updated
Unknown vulnerability in the regexreplace modifier (modifier.regexreplace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.
Affected Software
6 affected components
Smarty smarty=2.6.7
Smarty smarty=2.6.3
Smarty smarty=2.6.6
Smarty smarty=2.6.4
Smarty smarty=2.6.2
Smarty smarty=2.6.5
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 29, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0913?
CVE-2005-0913 is considered to have a critical severity level due to the potential for arbitrary PHP code execution.
2
How do I fix CVE-2005-0913?
To fix CVE-2005-0913, upgrade Smarty to version 2.6.8 or later.
3
What versions of Smarty are affected by CVE-2005-0913?
CVE-2005-0913 affects Smarty versions 2.6.2 to 2.6.7.
4
Can exploiting CVE-2005-0913 lead to data compromise?
Yes, exploiting CVE-2005-0913 can potentially lead to data compromise by allowing attackers to execute arbitrary PHP code.
5
Is CVE-2005-0913 still relevant today?
While CVE-2005-0913 is an older vulnerability, it is still relevant for systems that have not been updated to the patched version of Smarty.