PT-2010-3268 · Phpthumb+1 · Phpthumb+1

Published

2010-04-29

·

Updated

2017-08-17

·

CVE-2010-1598

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpThumb() version 1.7.9
Description The issue allows remote attackers to execute arbitrary commands when ImageMagick is installed. This is achieved via the fltr[] parameter. The problem was discovered in the wild in April 2010.
Recommendations For phpThumb() version 1.7.9, consider restricting access to the fltr[] parameter until a patch is available. As a temporary workaround, disabling the use of ImageMagick with phpThumb() may minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1598

Affected Products

Imagemagick
Phpthumb