The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.
Link | Tags |
---|---|
http://secunia.com/advisories/15534 | third party advisory patch |
http://sourceforge.net/project/shownotes.php?release_id=330469 | |
http://www.securityfocus.com/bid/13842 | vdb entry |