wannabie
Elite Member
- Mar 11, 2009
- 3,798
- 2,971
TENS OR HUNDREDS OF THOUSANDS of Wordpress installations are at risk of being compromised because of a critical vulnerability in a popular third-party image manipulation script called timthumb.
The affected image utility is not part of the main Wordpress package, but is incorporated in many popular Wordpress themes. The script consists of a single file called timthumb.php and facilitates on-the-fly image cropping, zooming and resizing.
Timthumb defines a white list of remote domain names from which images can be fetched by default, which include popular image hosting web sites like Flickr.com, Picasa.com, Blogger.com, Wordpress.com, Photobucket.com and others.
Read more: http://www.theinquirer.net/inquirer/news/2099162/wordpress-blogs-risk#ixzz1TyrhkHxK
The Inquirer - Computer hardware news and downloads. Visit the download store today.
Just so you know
The affected image utility is not part of the main Wordpress package, but is incorporated in many popular Wordpress themes. The script consists of a single file called timthumb.php and facilitates on-the-fly image cropping, zooming and resizing.
Timthumb defines a white list of remote domain names from which images can be fetched by default, which include popular image hosting web sites like Flickr.com, Picasa.com, Blogger.com, Wordpress.com, Photobucket.com and others.
Read more: http://www.theinquirer.net/inquirer/news/2099162/wordpress-blogs-risk#ixzz1TyrhkHxK
The Inquirer - Computer hardware news and downloads. Visit the download store today.
Just so you know