{"cve":"CVE-2011-4106","epss":{"score":0.23342},"mitre":{"cpes":[],"created":"2013-10-26T16:00:00+00:00","description":"TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2011/4xxx/CVE-2011-4106.json","references":["http://code.google.com/p/timthumb/issues/detail?id=212","http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/","http://markmaunder.com/2011/08/02/technical-details-and-scripts-of-the-wordpress-timthumb-php-hack/","http://www.binarymoon.co.uk/2011/08/timthumb-2/","http://www.exploit-db.com/exploits/17602","http://www.exploit-db.com/exploits/17872","http://www.openwall.com/lists/oss-security/2011/11/03/4"],"title":null,"updated":"2024-09-16T22:09:33.905000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:a:binarymoon:timthumb:*:*:*:*:*:*:*:*"],"created":"2013-10-26T16:55:03.113000+00:00","description":"TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.","metrics":{"cvssV2_0":{"score":6.8,"vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"nvd_repo_path":"2011/CVE-2011-4106.json","references":["http://code.google.com/p/timthumb/issues/detail?id=212","http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/","http://markmaunder.com/2011/08/02/technical-details-and-scripts-of-the-wordpress-timthumb-php-hack/","http://www.binarymoon.co.uk/2011/08/timthumb-2/","http://www.exploit-db.com/exploits/17602","http://www.exploit-db.com/exploits/17872","http://www.openwall.com/lists/oss-security/2011/11/03/4"],"title":null,"updated":"2026-06-16T23:34:26.127000+00:00","vendors":["binarymoon","binarymoon$PRODUCT$timthumb"],"weaknesses":["CWE-20"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:a:binarymoon:timthumb:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2013-10-26T16:00:00+00:00","provider":"mitre"},"description":{"data":"TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-listed domain in the src parameter, then accessing it via a direct request to the file in the cache directory, as exploited in the wild in August 2011.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":6.8,"vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.23342},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://code.google.com/p/timthumb/issues/detail?id=212","http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/","http://markmaunder.com/2011/08/02/technical-details-and-scripts-of-the-wordpress-timthumb-php-hack/","http://www.binarymoon.co.uk/2011/08/timthumb-2/","http://www.exploit-db.com/exploits/17602","http://www.exploit-db.com/exploits/17872","http://www.openwall.com/lists/oss-security/2011/11/03/4"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-04-11T00:51:21.963000+00:00","provider":"nvd"},"vendors":{"data":["binarymoon","binarymoon$PRODUCT$timthumb"],"providers":["nvd"]},"weaknesses":{"data":["CWE-20"],"providers":["nvd"]}}}