CVE-2006-7105
** DISPUTED **
PHP remote file inclusion vulnerability in libs/Smarty.class.php in Smarty 2.6.9 allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter. NOTE: in the original disclosure, filename is used in a function definition, so this report is probably incorrect.
Date published : 2007-03-03
http://www.securityfocus.com/bid/20557
http://www.security-express.com/archives/fulldisclosure/2006-10/0299.html