CVE-2013-6919

phpthumb < 1.7.12 - Server-Side Request Forgery via src Parameter

Title source: llm
STIX 2.1

Description

The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.

Scores

EPSS 0.0119
EPSS Percentile 64.1%

Details

Status published
Products (2)
james-heinrich/phpthumb 0 - 1.7.12Packagist
phpthumb_project/phpthumb < 1.7.11
Published Dec 27, 2014
Tracked Since Feb 18, 2026