Wordpress TimThumb Exploit (Remote Code Execution)
A lot of wordpress themes use timthumb script to resize images. From version 1.15 to 1.33 timthumb allows external domains such as flickr.com to display remote images on your website .
More detailed information here:
- Wordpress timthum hack
- Zero Day vulnerability in many wordpress themes
Resources:
- TimThumb version used
- Vulnerable wordpress theme
- List of vulnerable wordpress themes
More detailed information here:
- Wordpress timthum hack
- Zero Day vulnerability in many wordpress themes
Resources:
- TimThumb version used
- Vulnerable wordpress theme
- List of vulnerable wordpress themes
genial :O
ReplyDeletehow to make "fakeflickr.com/srv/http/thimthumb" on terminal backbox....
ReplyDeleteThx :)