← Back to browse · API

CVE-2006-7105

Severity
CRITICAL
CVSS
9.8
EPSS
0.01735
Risk score
39.81
CISA KEV
No
PoC
No
Published
2007-03-03
Modified
2025-01-17
First seen
2026-08-07
Aliases
EUVD-2006-7087, GHSA-JJPX-47JX-V4XX
Products
n/a:n/a n/a
Sources
euvd EUVD-2006-7087

Description

PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect

References