CVE-2011-1028: Input Validation
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smartyinternalcompileprivatespecialvariable.php file.
Other sources
The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smartyinternalcompileprivatespecialvariable.php file.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1028?
CVE-2011-1028 has been classified with high severity due to the potential for arbitrary PHP code execution.
How do I fix CVE-2011-1028?
To fix CVE-2011-1028, update Smarty to version 3.0.7 or later.
Which versions are affected by CVE-2011-1028?
CVE-2011-1028 affects Smarty versions prior to 3.0.7 and specific Debian Linux versions including 8.0, 9.0, and 10.0.
What is the impact of CVE-2011-1028?
The impact of CVE-2011-1028 allows attackers to execute arbitrary PHP code, leading to potential system compromise.
Is there a workaround for CVE-2011-1028?
As a temporary workaround for CVE-2011-1028, avoid using the vulnerable $smarty.template variable until you can apply the fix.