Skip to content

Comment on Zero Day Vulnerability in many Wordpress Themesparent

Comments

On a CubeCart pluggin that had the same flaw as the timthumb.php one, I whitelisted image file extensions. This should work, as long as there aren't and local file include vulnerabilities in the site.

This still allows the attacker to host images on your site though.

> This still allows the attacker to host images on your site though.

Well put.

Probably best to remove allowed hosts altogether.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.