Back to search
CVE-2011-4106
Published: Oct 26, 2013
Modified: Sep 16, 2024
PUBLISHED
Description
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
17872
exploit
x_refsource_EXPLOIT-DB
http://www.binarymoon.co.uk/2011/08/timthumb-2/
x_refsource_CONFIRM
[oss-security] 20111103 Re: CVE request: wordpress plugin timthumb before 2.0 remote code execution
mailing-list
x_refsource_MLIST
17602
exploit
x_refsource_EXPLOIT-DB
http://code.google.com/p/timthumb/issues/detail?id=212
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now