Skip to content
Noroxi

phpThumb project records

2 published records for vendor phpthumb project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

2 records
  • Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTM

    MediumCVSS 6.1No exploitEPSS 1%

    phpthumb project · phpthumbAug 31, 2017

  • CVE-2013-6919
    17Monitor

    The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct

    MediumCVSS 4.3No exploitEPSS 1%

    phpthumb project · phpthumbDec 27, 2014