CVE Vulnerabilities

CVE-2005-1898

Published: Jun 09, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.

Affected Software

NameVendorStart VersionEnd Version
PhpthumbPhpthumb1.5 (including)1.5 (including)
PhpthumbPhpthumb1.5.1 (including)1.5.1 (including)
PhpthumbPhpthumb1.5.2 (including)1.5.2 (including)
PhpthumbPhpthumb1.5.3 (including)1.5.3 (including)

References