PHP remote file inclusion vulnerability in unit_test/test_cases.php in Smarty 2.6.1 allows remote attackers to execute arbitrary PHP code via a URL in the SMARTY_DIR parameter. NOTE: this issue is disputed by CVE and a third party because SMARTY_DIR is a constant
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=116163668213491&w=2 | mailing list exploit |
http://osvdb.org/31096 | vdb entry |
http://marc.info/?l=bugtraq&m=116170769322920&w=2 | mailing list exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29739 | vdb entry |