The passthrough functionality in phpThumb.php in phpThumb() prior to 1.5.4 allows remote malicious users to read files that are not images.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpthumb phpthumb 1.5.3 |
||
phpthumb phpthumb 1.5 |
||
phpthumb phpthumb 1.5.1 |
||
phpthumb phpthumb 1.5.2 |