The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not...
7AI Score
0.002EPSS
Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in...
6.1CVSS
6AI Score
0.001EPSS
The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src...
7AI Score
0.002EPSS