PT-2014-3216 · Phpthumb · Phpthumb

Deepankar Arora

+1

·

Published

2014-12-27

·

Updated

2022-05-17

·

CVE-2013-6919

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions phpThumb versions prior to 1.7.12
Description The issue concerns the default configuration of phpThumb, where the disable debug option is set to false, allowing remote attackers to conduct Server-Side Request Forgery (SSRF) attacks. This is achieved by exploiting the src parameter.
Recommendations For versions prior to 1.7.12, update to version 1.7.12 or later to resolve the issue. As a temporary workaround, consider setting the disable debug option to true to prevent SSRF attacks via the src parameter.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6919
GHSA-3747-GJC9-VVG6

Affected Products

Phpthumb