CVE-2010-1598 Information
Feb 14, 2021
cve
Description
phpThumb.php in phpThumb() 1.7.9 and possibly other versions when ImageMagick is installed allows remote attackers to execute arbitrary commands via the fltr[] parameter as discovered in the wild in April 2010. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Reference
http://modx.com/blog/2014/01/21/revolution-2.2.11E28094security-fixes-and-prevent-change-loss http://osvdb.org/63939 http://secunia.com/advisories/39556 http://secunia.com/advisories/57038 http://www.securityfocus.com/bid/39605 https://exchange.xforce.ibmcloud.com/vulnerabilities/58040
Share on: