SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-4106

TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via…

MEDIUM 6.8EPSS 23.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 23.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
23.16% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
binarymoon/timthumb
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.