PT-2014-6048 · Webshot+2 · Webshot+2

Published

2014-07-15

·

Updated

2014-07-15

·

CVE-2014-4663

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TimThumb version 2.8.13 WordThumb version 1.07
Description The issue allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter when Webshot (also known as Webshots) is enabled.
Recommendations For TimThumb version 2.8.13, consider disabling Webshot until a patch is available. For WordThumb version 1.07, avoid using the src parameter in affected API endpoints until the issue is resolved.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4663

Affected Products

Timthumb
Webshot
Wordthumb