CVE-2009-5053: High severity smarty vulnerability
Published Feb 3, 2011
·Updated
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
Affected Software
63 affected components
Smarty smarty=1.4.3
Smarty smarty=1.0
Smarty smarty=1.0b
Smarty smarty=2.3.1
Smarty smarty=2.6.0-rc3
Smarty smarty=2.6.25
Smarty smarty=1.4.0
Smarty smarty=1.4.5
Smarty smarty=2.6.1
Smarty smarty=2.6.7
Smarty smarty=2.6.20
Smarty smarty=2.3.0
Smarty smarty=1.0a
Smarty smarty=1.1.0
Smarty smarty=1.4.0-b2
Smarty smarty=2.6.0
Smarty smarty=2.6.15
Smarty smarty=2.6.3
Smarty smarty=2.6.14
Smarty smarty=2.5.0-rc1
Smarty smarty=1.2.1
Smarty smarty=2.6.17
Smarty smarty=2.6.11
Smarty smarty=2.6.0-rc2
Smarty smarty=1.3.0
Smarty smarty=1.4.1
Smarty smarty=2.5.0-rc2
Smarty smarty=2.0.1
Smarty smarty=2.5.0
Smarty smarty=1.4.2
Smarty smarty=1.5.0
Smarty smarty=2.1.0
Smarty smarty=2.6.22
Smarty smarty=1.5.2
Smarty smarty=2.6.12
Smarty smarty=2.6.18
Smarty smarty=1.5.1
Smarty smarty=2.0.0
Smarty smarty=2.4.1
Smarty smarty=2.6.6
Smarty smarty=2.6.26
Smarty smarty=2.6.16
Smarty smarty=2.6.9
Smarty smarty=1.2.2
Smarty smarty=2.6.0-rc1
Smarty smarty=2.6.24
Smarty smarty=2.1.1
Smarty smarty=2.6.4
Smarty smarty=2.2.0
Smarty smarty=2.4.2
Smarty smarty=2.6.10
Smarty smarty<=3.0.0
Smarty smarty=2.6.2
Smarty smarty=1.4.0-b1
Smarty smarty=2.6.13
Smarty smarty=3.0.0-beta4
Smarty smarty=2.6.5
Smarty smarty=1.3.2
Smarty smarty=2.4.0
Smarty smarty=1.3.1
Smarty smarty=1.4.4
Smarty smarty=1.4.6
Smarty smarty=1.2.0
Event History
Feb 3, 2011
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-5053?
CVE-2009-5053 is classified as a high severity vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2009-5053?
To fix CVE-2009-5053, upgrade Smarty to version 3.0.0 beta 6 or later.
3
What versions of Smarty are affected by CVE-2009-5053?
CVE-2009-5053 affects all versions of Smarty before 3.0.0 beta 6.
4
Can CVE-2009-5053 be exploited remotely?
Yes, CVE-2009-5053 can be exploited remotely by injecting arbitrary PHP code into cache files.
5
What are the potential impacts of CVE-2009-5053?
The potential impacts of CVE-2009-5053 include unauthorized execution of arbitrary PHP code, leading to full server compromise.