|
|||||||
19/05/2012 17:29
Yes. All requests made in order to exploit this vulnerability are denied with a "Precondition Failed" error message.
Mass infection of WordPress sites due to TimThumb
Recently a new high risk vulnerability was discovered in the highly popular TimThumb script. TimThumb is a “A small php script for cropping, zooming and resizing web images (jpg, png, gif). Perfect for use on blogs and other applications.“
TimThumb is included in a lot of WordPress plugins and themes (free and paid). Exploiting this vulnerability an attacker can upload and excute a PHP file of his choice on a vulnerable website.