wordpress timthumb.php vulnerability -


i trying upload remotely php file web page, has timthumb version : 1.28 known timthumb.php vurnable file. after upload php file when open cache doesnt execute! dont know stops executing! saw changes made in timthumb.php add .txt every file goes cache folder, added in newer version not in version, confused stops executing! way learning purpose.

if file's named whatever.php.txt on server, it's going seen text file server, not php file, , served such. tell server treat .txt files php files, which'd run file+code through php interpreter, you've re-opened security hole timthumb patched .txt addition.

e.g. you'd still vulnerable remote hacks.


Comments

Popular posts from this blog

java - Play! framework 2.0: How to display multiple image? -

gmail - Is there any documentation for read-only access to the Google Contacts API? -

php - Controller/JToolBar not working in Joomla 2.5 -