CVE-2006-7105: Code Injection
DISPUTED PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-7105?
CVE-2006-7105 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2006-7105?
To fix CVE-2006-7105, upgrade to the latest version of Smarty that addresses the remote file inclusion vulnerability.
What is the impact of CVE-2006-7105?
The impact of CVE-2006-7105 allows attackers to execute arbitrary PHP code, compromising the security of the affected application.
Which version of Smarty is affected by CVE-2006-7105?
CVE-2006-7105 specifically affects Smarty version 2.6.9.
Is CVE-2006-7105 still a concern for current applications?
CVE-2006-7105 could be a concern for legacy applications still using the vulnerable Smarty version, making it important to assess and mitigate.