TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload…
redhat·CWE-20·Published 2013-10-26