CVE-2014-4663
15.07.2014, 14:55
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.
Vendor | Product | Version |
---|---|---|
binarymoon | timthumb | 2.8.13 |
binarymoon | wordthumb | 1.07 |
𝑥
= Vulnerable software versions
References