VYPR
Critical severity9.8NVD Advisory· Published Nov 20, 2019· Updated Jun 16, 2026

CVE-2011-1028

CVE-2011-1028

Description

The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
smarty/smartyPackagist
< 3.0.73.0.7

Affected products

6
  • cpe:2.3:a:smarty:smarty:*:*:*:*:*:*:*:*
    Range: >=3.0.0,<3.0.7
  • Debian/linux3 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 3.0.7
  • smarty3/smarty3v5
    Range: 3

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.