Back

HIGH

smarty arbitrary code execution in template

Published Feb 28, 2008

Description

The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PHP functions via templates, related to a '\0' character in a search string.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (21)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 28, 2008
Updated Aug 7, 2024
Reserved Feb 28, 2008
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a