Security Advisory
CVE-2014-4663
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.