peter bassill · operator
$ cve CVE-2014-4663 JSON

CVE-2014-4663 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS9.75% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2014-07-15
Last modified2026-06-17

Affected (2)

VendorProduct
binarymoontimthumb
binarymoonwordthumb

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD