vendor:
TimThumb
by:
MaXe
7,5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: TimThumb
Affected Version From: 1.*
Affected Version To: 1.32
Patch Exists: YES
Related CWE: N/A
CPE: a:timthumb:timthumb
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP + Apache + PHP (XAMPP)
2011
WordPress TimThumb Plugin – Remote Code Execution
TimThumb is an image resizing utility, widely used in many WordPress themes. It is prone to a Remote Code Execution vulnerability, due to the script does not check remotely cached files properly. By crafting a special image file with a valid MIME-type, and appending a PHP file at the end of this, it is possible to fool TimThumb into believing that it is a legitimate image, thus caching it locally in the cache directory.
Mitigation:
Upgrade to the latest version of TimThumb.