timthumb.php wordpress plugin remote code execution


Description   This signature detects and blocks any attempt to exploit a remote code execution vulnerability in TimThumb. Indeed TimThumb does not check remotely cached files properly. By crafting a special image file with a valid MIME-type, and appending a PHP file at the end of this, it is possible to fool TimThumb into believing that it is a legitimate image, thus caching it locally in the cache directory.
     
Default
configuration
 
Profiles High Medium Low Internet
Action Block Block Block Block
Alarm Level Major Major Minor Minor
     
References   URL: http://markmaunder.com/2011/zero-day-vulnerability-in-many-wordpress-themes/
     
Available since   ASQ v4.1.2
     
Protects   Wordpress Multiple Third Party Plugins Multiple Vulnerabilities
100 last CVE   CVE-2015-6668


 
 
 
 
 Risk level 
High