CVE-2014-4663

EXPLOITED

TimThumb 2.8.13-WordThumb 1.07 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2014-4663 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including @u0x.

AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in TimThumb 2.8.13 and WordThumb 1.07 via the WebShot feature. The vulnerability arises from insufficient input sanitization in the 'src' parameter, allowing arbitrary command execution through shell metacharacters.

Description

TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by @u0x · textwebappsphp
https://www.exploit-db.com/exploits/33851

This exploit demonstrates a command injection vulnerability in TimThumb 2.8.13 and WordThumb 1.07 via the WebShot feature. The vulnerability arises from insufficient input sanitization in the 'src' parameter, allowing arbitrary command execution through shell metacharacters.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: TimThumb 2.8.13, WordThumb 1.07
No auth needed
Prerequisites: WebShot feature enabled · CutyCapt and XVFB installed on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q2/689
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jul/4
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jun/117
Issue Tracking x_refsource_confirm
https://code.google.com/p/timthumb/issues/detail?id=485
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59558
Issue Tracking x_refsource_confirm
https://code.google.com/p/timthumb/source/detail?r=219
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/33851

Scores

EPSS 0.0975
EPSS Percentile 94.9%

Details

VulnCheck KEV 2024-10-15
CWE
CWE-94
Status published
Products (2)
binarymoon/timthumb 2.8.13
binarymoon/wordthumb 1.07
Published Jul 15, 2014
Tracked Since Feb 18, 2026