A new vulnerability has been disclosed on TimThumbs Webshot feature that allows for certain commands to be executed on the vulnerable website remotely. With a simple command, an attacker can create, remove and modify any files on your server. Timthumb comes with the webshot option disabled by default, so just a few Tim Thumb installations are vulnerable. The full disclosure is available here for anyone interested in more technical details. You have to check whether your Timthum file does not have this option enabled to prevent it from being misused.”]
Source: https://blog.sucuri.net/2014/06/timthumb-webshot-code-execution-exploit-0-day.html

