PT-2010-3268 · Phpthumb+1 · Phpthumb+1

Publicado

2010-04-29

·

Atualizado

2017-08-17

·

CVE-2010-1598

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpThumb() version 1.7.9
Description The issue allows remote attackers to execute arbitrary commands when ImageMagick is installed. This is achieved via the fltr[] parameter. The problem was discovered in the wild in April 2010.
Recommendations For phpThumb() version 1.7.9, consider restricting access to the fltr[] parameter until a patch is available. As a temporary workaround, disabling the use of ImageMagick with phpThumb() may minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1598

Produtos afetados

Imagemagick
Phpthumb