This release addresses a fix to the /regex_replace/ modifier
that ships
with Smarty. It was possible to apply the "e"
(eval) PCRE flag to
replacement text with carefully crafted spacing. Those of
you who use
Smarty with security enabled, it is recommended that you
upgrade.
This is the only change since 2.6.12. For a quick-fix, just
replace the
/modifier.regex_replace.php/ file in the plugins directory.
http://smarty.php.net/
--
Smarty General Mailing List (http://smarty.php.net/)
To unsubscribe, visit: http://www.php.net/unsub
.php
|