Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.exploit-db.com/exploits/18075 - | |
References | () http://www.phpletter.com/en/DOWNLOAD/1/ - | |
References | () http://www.phpmyfaq.de/advisory_2011-10-25.php - | |
References | () http://www.securityfocus.com/bid/50523 - Exploit | |
References | () http://www.zenphoto.org/trac/ticket/2005 - |
Information
Published : 2011-12-15 03:57
Updated : 2024-11-21 01:33
NVD link : CVE-2011-4825
Mitre link : CVE-2011-4825
CVE.ORG link : CVE-2011-4825
JSON object : View
Products Affected
phpmyfaq
- phpmyfaq
phpletter
- ajax_file_and_image_manager
tinymce
- tinymce
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')