Topic: Zero Day Vulnerability in timthumb script
There have been reports that versions prior to 1.3.4 of timthumb script have a serious security vulnerability that allows hackers to access sensitive information from your web server via the script.
http://markmaunder.com/2011/zero-day-vu … ss-themes/
As such, it is HIGHLY RECOMMENDED that you update the timthumb script to its latest version to fix the security hole.
Two ways to patch the theme for timthumb:
1. Download timthumb and overwrite the file at /wp-content/themes/arras/library/timthumb.php:
http://timthumb.googlecode.com/svn/trunk/timthumb.php
2. If you are not using timthumb as your primary thumbnail management method, you can simply replace timthumb.php with a blank file.
3. Download Arras 1.5.1.2 with TimThumb functionality removed:
http://arras-theme.googlecode.com/files … mthumb.zip
There may be plans to remove timthumb support for the next major version of the theme, in favour of WordPress' built-in post thumbnail system. I'll give more details about it in the next future.
Last edited by zy (2011-09-26 19:44:04)