Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PHPThumb Arbitrary File Information Disclosure Vulnerability

phpThumb is prone to an information disclosure vulnerability. This is due to a failure in the application to properly sanitize user-supplied input.

By design the application displays detailed information of picture files. The problem presents itself due to a failure in the application to ensure the file being displayed is a picture file.

An attacker may exploit this vulnerability to retrieve the contents of arbitrary files with the privileges of the Web server process. This information could be used to aid in further attacks against the underlying system.







 

Privacy Statement
Copyright 2008, SecurityFocus