References https://avd.aliyun.com/detail?id=AVD-2017-1000480 https://cloud.tencent.cn/developer/article/1939281 https://zhuanlan.zhihu.com/p/501811049 https://www.cnblogs.com/congyou/p/19022559 https://blog.csdn.net/weixin_28801391/article/details/116530419 https://security.zone.ci/aliyun/ali_nvd/101799.html http://chybeta.github.io/2018/01/23/CVE-2017-1000480-Smarty-3-1-32-php%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C-%E6%BC%8F%E6%B4%9E%E5%88%86%E6%9E%90/ https://blog.spoock.com/2018/03/06/Smartyty-RCE-Analysis/ https://www.venustech.com.cn/new_type/aqtg/20210226/22409.html https://www.cnblogs.com/jinyanshenxing/p/15832670.html https://cloud.tencent.com/developer/article/2283067 https://www.sentinelone.com/vulnerability-database/cve-2021-26120/ https://srcincite.io/advisories/src-2021-0010/ https://nvd.nist.gov/vuln/detail/CVE-2021-26120 https://exchange.xforce.ibmcloud.com/vulnerabilities/197150 https://github.com/smarty-php/smarty/security/advisories/GHSA-4rmg-292m-wg3w https://www.sangfor.com/blog/cybersecurity/php-smarty-sandbox-escape-vulnerability-cve-2021-26119
Related VulnerabilitiesPoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-48611: phpBB < 3.3.17 - Authentication BypassPoCCVE-2026-46364: phpMyFAQ <= 4.1.1 - SQL InjectionPoCCVE-2026-6433: FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionphpVMS /importer 未授权访问漏洞(CVE-2026-42569)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSphpMyFAQ /api/captcha SQL 注入漏洞PoCCVE-2026-42569: phpVMS < 7.0.6 - Legacy Importer Authorization BypassphpVMS存在权限绕过漏洞(CVE-2026-42569)PoCCVE-2020-26935: phpMyAdmin < 5.0.3 - SQL InjectionPoCphp-prober-exposure: PHP Prober - ExposurePoCcakephp-debugkit-exposure: CakePHP - Debug Kit Toolbar ExposurePoCCVE-2025-69200: phpMyFAQ - Configuration Backup Disclosure