cve/2018/CVE-2018-16831.md
2024-06-18 02:51:15 +02:00

618 B

CVE-2018-16831

Description

Smarty before 3.1.33-dev-4 allows attackers to bypass the trusted_dir protection mechanism via a file:./../ substring in an include statement.

POC

Reference

Github