6.8
CVSSv2

CVE-2010-1598

Published: 29/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

phpThumb.php in phpThumb() 1.7.9 and possibly other versions, when ImageMagick is installed, allows remote malicious users to execute arbitrary commands via the fltr[] parameter, as discovered in the wild in April 2010. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

silisoftware phpthumb\\(\\) 1.7.9

Exploits

Joomla Flexicontent component suffers from a code execution vulnerability due to the inclusion of phpthumb ...

Github Repositories

A simple python script which tries to find domains that still use vulnerable phpThumb versions.

What is this about This is a script I made which scrapes the web using dorks to find domains that still use vulnerable versions of the phpThumb php script What is phpThumb phpThumb is basically a PHP script that provides image resizing, cropping, and manipulation capabilities for web applications when loading images basically It is often used as a server-side image processing