Moderate severityNVD Advisory· Published Dec 27, 2014· Updated Jun 17, 2026
CVE-2013-6919
CVE-2013-6919
Description
The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote attackers to conduct Server-Side Request Forgery (SSRF) attacks via the src parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
james-heinrich/phpthumbPackagist | < 1.7.12 | 1.7.12 |
Affected products
2Patches
Vulnerability mechanics
References
6- www.rafayhackingarticles.net/2013/11/phpthumb-server-side-request-forgery.htmlnvdExploitWEB
- github.com/advisories/GHSA-3747-gjc9-vvg6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-6919ghsaADVISORY
- github.com/JamesHeinrich/phpThumb/blob/7ee966b38ddd7eb4d8091389aa514604710711c8/docs/phpthumb.changelog.txtghsaWEB
- github.com/JamesHeinrich/phpThumb/commit/457a37d4a22ac9cdbbfe19577376622e58df81b0ghsaWEB
- github.com/JamesHeinrich/phpThumb/blob/master/docs/phpthumb.changelog.txtnvd
News mentions
0No linked articles in our index yet.