{"id":"GHSA-6frx-2r5w-c524","summary":"Smarty3 Arbitrary PHP Code Execution","details":"The `$smarty.template` variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the `sysplugins/smarty_internal_compile_private_special_variable.php` file.","aliases":["CVE-2011-1028"],"modified":"2024-02-16T08:21:02.337201Z","published":"2022-04-22T00:24:15Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-01-12T22:38:45Z","nvd_published_at":"2019-11-20T15:15:00Z","cwe_ids":["CWE-20"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-1028"},{"type":"WEB","url":"https://github.com/smarty-php/smarty/commit/0154f17de2b2dd16ff9c016923015ac19af9c0cb"},{"type":"PACKAGE","url":"https://github.com/smarty-php/smarty"},{"type":"WEB","url":"https://seclists.org/oss-sec/2011/q1/313"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2011-1028"},{"type":"WEB","url":"https://web.archive.org/web/20110609032516/http://smarty-php.googlecode.com/svn/trunk/distribution/change_log.txt"},{"type":"WEB","url":"https://www.smarty.net/forums/viewtopic.php?t=18815"}],"affected":[{"package":{"name":"smarty/smarty","ecosystem":"Packagist","purl":"pkg:composer/smarty/smarty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.7"}]}],"versions":["v2.6.24","v2.6.25","v2.6.26","v2.6.27","v2.6.28","v2.6.29","v2.6.30","v2.6.31","v2.6.33"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-6frx-2r5w-c524/GHSA-6frx-2r5w-c524.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}