Description
TimThumb is a small php script for cropping, zooming and resizing web images (jpg, png, gif). Many WordPress themes and plugins distribute this script. A remote code execution vulnerability was reported in the WebShot feature of this script. This vulnerability was reported in v2.8.13 but previous versions are also vulnerable.
Remediation
Upgrade to the latest version of timthumb or disable the WebShot feature (if enabled).
References
Related Vulnerabilities
XWiki Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-46243)
CodeIgniter weak encryption key
Drupal Core 8.6.x Remote Code Execution (8.6.0 - 8.6.9)
Python Debugger Unauthorized Access Vulnerability
WordPress Plugin PHP Everywhere Multiple Remote Code Execution Vulnerabilities (2.0.3)