CVE-2009-1669
Publication date 18 May 2009
Last updated 24 July 2024
Ubuntu priority
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.
Status
Package | Ubuntu Release | Status |
---|---|---|
gallery2 | ||
moodle | ||
smarty | ||
Notes
mdeslaur
may be a PoC here: http://www.milw0rm.com/exploits/8659 Debian says: TODO: check. It should be windows specific.