在 Smarty 4.5.8 之前版本以及 5.x 中早于 5.8.5 的版本中,存在一个代码注入漏洞。该漏洞发生在 extends:/多组件模板继承机制中,顶级 nocache_hash 变量在继承过程中从未被恢复,导致其值为空(null)。攻击者可以构造包含伪造的 SmartyNocache 标记的赋值数据,该标记会被原样复制并写入重新生成的 PHP 缓存文件中。当缓存文件被包含(include)时,将执行任意 PHP 代码,从而导致远程代码执行(RCE)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| smarty-php | smarty | 0 ~ 4.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet