4.3
CVSSv2

CVE-2013-6919

Published: 27/12/2014 Updated: 29/12/2014
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The default configuration of phpThumb prior to 1.7.12 has a false value for the disable_debug option, which allows remote malicious users to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

phpthumb project phpthumb

Github Repositories

A simple python script which tries to find domains that still use vulnerable phpThumb versions.

What is this about This is a script I made which scrapes the web using dorks to find domains that still use vulnerable versions of the phpThumb php script What is phpThumb phpThumb is basically a PHP script that provides image resizing, cropping, and manipulation capabilities for web applications when loading images basically It is often used as a server-side image processing