Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2009-1669
Description:The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.
Test IDs: 1.3.6.1.4.1.25623.1.0.64322   1.3.6.1.4.1.25623.1.0.67847   1.3.6.1.4.1.25623.1.0.64080   1.3.6.1.4.1.25623.1.0.64078   1.3.6.1.4.1.25623.1.0.64079   1.3.6.1.4.1.25623.1.0.66103  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2009-1669
BugTraq ID: 34918
http://www.securityfocus.com/bid/34918
https://www.exploit-db.com/exploits/8659
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01283.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01287.html
https://www.redhat.com/archives/fedora-package-announce/2009-May/msg01274.html
http://osvdb.org/54380
http://secunia.com/advisories/35072
http://secunia.com/advisories/35219
http://www.ubuntu.com/usn/usn-791-3
XForce ISS Database: smarty-smartyfunctionmath-cmd-execution(50457)
https://exchange.xforce.ibmcloud.com/vulnerabilities/50457




© 1998-2025 E-Soft Inc. All rights reserved.