CVE-2011-4106
EXPLOITED IN THE WILDTimThumb <2.0 - RCE
Title source: llmDescription
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.
Exploits (2)
Scores
EPSS
0.2633
EPSS Percentile
96.3%
Details
VulnCheck KEV
2013-10-26
InTheWild.io
2013-10-28
CWE
CWE-20
Status
published
Products (1)
binarymoon/timthumb
< 1.99
Published
Oct 26, 2013
Tracked Since
Feb 18, 2026