Binarymoon / Timthumb
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2010-5303 | Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remot… | MEDIUM | 4.3 | Aug 21, 2014 |
| CVE-2010-5302 | Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to… | MEDIUM | 4.3 | Aug 21, 2014 |
| CVE-2009-5142 | Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb 1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products, allows remote attackers t… | MEDIUM | 4.3 | Aug 21, 2014 |
| CVE-2014-4663 | TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in t… | MEDIUM | 6.8 | Jul 15, 2014 |
| CVE-2011-4106 | TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrar… | MEDIUM | 6.8 | Oct 26, 2013 |
Showing 1 to 5 of 5 CVEs