Get a Pentest and security assessment of your IT network.

Cyber Security

Zero-day flaw in WordPress image utility allows to upload files and execute codes

TimThumb is a free image resizing utility widely used on the blogging platform WordPress. Mark Maunder, CEO of Feedjit, discovered the flaw after his own blog was hacked to load advertising content. The utility only does a partial match on hostnames allowing hackers to upload and execute arbitrary PHP code in your timthumb cache directory. An attacker could upload files and execute code on an affected site without the owner’s permission. The latest version of the utility is affected by the issue.

Source: https://thehackernews.com/2011/08/zero-day-flaw-in-wordpress-image.html

Related posts
Cyber Security

Zip Codes & PII: Are They Personal Data?

Cyber Security

Zero-Day Vulnerabilities: User Defence Guide

Cyber Security

Zero Knowledge Voting with Trusted Server

Cyber Security

ZeroNet: 51% Attack Risks & Mitigation