CVE-2014-8350: Code Injection
Published Oct 19, 2014
·Updated
Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.
Affected Software
102 affected componentsFixes available
composer/smarty/smarty<3.1.21
3.1.21
debian/smarty3<=3.1.10-2, <=3.0~rc1-1
Smarty smarty<=3.1.20
Smarty smarty=1.0
Smarty smarty=1.0a
Smarty smarty=1.0b
Smarty smarty=1.1.0
Smarty smarty=1.2.0
Smarty smarty=1.2.1
Smarty smarty=1.2.2
Smarty smarty=1.3.0
Smarty smarty=1.3.1
Smarty smarty=1.3.2
Smarty smarty=1.4.0
Smarty smarty=1.4.0-b1
Smarty smarty=1.4.0-b2
Smarty smarty=1.4.1
Smarty smarty=1.4.2
Smarty smarty=1.4.3
Smarty smarty=1.4.4
Smarty smarty=1.4.5
Smarty smarty=1.4.6
Smarty smarty=1.5.0
Smarty smarty=1.5.1
Smarty smarty=1.5.2
Smarty smarty=2.0.0
Smarty smarty=2.0.1
Smarty smarty=2.1.0
Smarty smarty=2.1.1
Smarty smarty=2.2.0
Smarty smarty=2.3.0
Smarty smarty=2.3.1
Smarty smarty=2.4.0
Smarty smarty=2.4.1
Smarty smarty=2.4.2
Smarty smarty=2.5.0
Smarty smarty=2.5.0-rc1
Smarty smarty=2.5.0-rc2
Smarty smarty=2.6.0
Smarty smarty=2.6.0-rc1
Smarty smarty=2.6.0-rc2
Smarty smarty=2.6.0-rc3
Smarty smarty=2.6.1
Smarty smarty=2.6.2
Smarty smarty=2.6.3
Smarty smarty=2.6.4
Smarty smarty=2.6.5
Smarty smarty=2.6.6
Smarty smarty=2.6.7
Smarty smarty=2.6.9
Smarty smarty=2.6.10
Smarty smarty=2.6.11
Smarty smarty=2.6.12
Smarty smarty=2.6.13
Smarty smarty=2.6.14
Smarty smarty=2.6.15
Smarty smarty=2.6.16
Smarty smarty=2.6.17
Smarty smarty=2.6.18
Smarty smarty=2.6.20
Smarty smarty=2.6.22
Smarty smarty=2.6.24
Smarty smarty=2.6.25
Smarty smarty=2.6.26
Smarty smarty=3.0.0
Smarty smarty=3.0.0-beta4
Smarty smarty=3.0.0-beta5
Smarty smarty=3.0.0-beta6
Smarty smarty=3.0.0-beta7
Smarty smarty=3.0.0-beta8
Smarty smarty=3.0.0-rc1
Smarty smarty=3.0.0-rc2
Smarty smarty=3.0.0-rc3
Smarty smarty=3.0.0-rc4
Smarty smarty=3.0.1
Smarty smarty=3.0.2
Smarty smarty=3.0.3
Smarty smarty=3.0.4
Smarty smarty=3.0.5
Smarty smarty=3.0.6
Smarty smarty=3.0.7
Smarty smarty=3.1-rc1
Smarty smarty=3.1.0
Smarty smarty=3.1.1
Smarty smarty=3.1.2
Smarty smarty=3.1.3
Smarty smarty=3.1.4
Smarty smarty=3.1.5
Smarty smarty=3.1.6
Smarty smarty=3.1.7
Smarty smarty=3.1.8
Smarty smarty=3.1.9
Smarty smarty=3.1.10
Smarty smarty=3.1.11
Smarty smarty=3.1.12
Smarty smarty=3.1.13
Smarty smarty=3.1.14
Smarty smarty=3.1.15
Smarty smarty=3.1.16
Smarty smarty=3.1.17
Smarty smarty=3.1.18
Smarty smarty=3.1.19
Event History
Nov 3, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·01:13 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-8350?
CVE-2014-8350 has a medium severity rating as it allows remote code execution due to a vulnerability in Smarty before version 3.1.21.
2
How do I fix CVE-2014-8350?
To fix CVE-2014-8350, upgrade Smarty to version 3.1.21 or later.
3
Which versions are affected by CVE-2014-8350?
CVE-2014-8350 affects all Smarty versions before 3.1.21, including several earlier versions like 1.x and 2.x.
4
Can CVE-2014-8350 be exploited remotely?
Yes, CVE-2014-8350 can be exploited remotely by attackers to execute arbitrary PHP code via crafted templates.
5
Is there a patch for CVE-2014-8350?
There is no separate patch for CVE-2014-8350; the only solution is to upgrade to the fixed version 3.1.21.