Update pi.teethumb.php to new safe version

  • Problem
  • Updated 4 years ago
Hi,

I've been made aware that the original version of timthumb or teethumb image resizer has security vunerabilities in it. (mediatemple deleted the file on me and pointed me to woothemes support). I've tried to find answers on woothemes but everything requires an account, and I don't want to pay for one cause I bought the city guide EE theme from themeforest.net.

Anyway, I need an updated pi.teethumb.php file for my theme cause at the moment the whole site doesn't work. I can't reload the old one or mediatemple will close my account but the update I found on woothemes only seems to be for wordpress sites not EE. (http://timthumb.googlecode.com/svn/tr...)

Could you help out with a replacement file.

I've read the following pages without success:
http://www.woothemes.com/2011/08/timt...
http://weblog.mediatemple.net/2011/08...
http://blog.sucuri.net/2011/08/attack...

Thanks,

Chris
Photo of Chris Sandford

Chris Sandford

  • 1 Post
  • 0 Reply Likes

Posted 4 years ago

  • 1
Photo of Bjørn Børresen

Bjørn Børresen, Company Admin

  • 1159 Posts
  • 39 Reply Likes
Hi,

pi.teemthumb.php never had this security vulnerability as it never accepted input from _GET/_POST (unlike the original timthumb script).