CVE-2008-4811: High severity smarty vulnerability
The expandquotedtext function in libs/SmartyCompiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a \ (backslash) before a dollar-sign character.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4811?
CVE-2008-4811 has a high severity level due to its ability to allow remote attackers to execute arbitrary PHP code.
How do I fix CVE-2008-4811?
To fix CVE-2008-4811, upgrade Smarty to version 2.6.21 or later, which addresses the vulnerability.
What versions are affected by CVE-2008-4811?
CVE-2008-4811 affects multiple versions of Smarty, including all versions prior to 2.6.21.
Can CVE-2008-4811 be exploited without authentication?
Yes, CVE-2008-4811 can be exploited remotely without authentication, making it particularly dangerous.
What is the impact of CVE-2008-4811?
The impact of CVE-2008-4811 includes potential unauthorized access and control of the affected system due to arbitrary PHP code execution.