PT-2014-3216 · Phpthumb · Phpthumb

Deepankar Arora

+1

·

Publicado

2014-12-27

·

Atualizado

2022-05-17

·

CVE-2013-6919

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpThumb versions prior to 1.7.12
Description The issue concerns the default configuration of phpThumb, where the disable debug option is set to false, allowing remote attackers to conduct Server-Side Request Forgery (SSRF) attacks. This is achieved by exploiting the src parameter.
Recommendations For versions prior to 1.7.12, update to version 1.7.12 or later to resolve the issue. As a temporary workaround, consider setting the disable debug option to true to prevent SSRF attacks via the src parameter.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-6919
GHSA-3747-GJC9-VVG6

Produtos afetados

Phpthumb