logo       

Re: smarty security problem: msg#00040

php.tcphp

Subject: Re: smarty security problem

I am sure that many on thislist use Smarty. If you haven't seen this already, you probably should check out this notice

<http://www.securityfocus.com/bid/12941?ref=rss>

Not to be picky, but the description of the problem at the URL noted is useless.

http://smarty.php.net/ has a concise description of the problem. Basically,
if you are using template security and allowing non-trusted users to write
templates, those templates can be used to execute arbitrary PHP code.

-Bob


<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise