CVE-2011-4825

Scores

EPSS

0.830high83.0%
0%20%40%60%80%100%

Percentile: 83.0%

CVSS

7.5high2.0
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvdubuntu

CWEs

CWE-94

Exploits

Exploit ID: 18075

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18075

Exploit ID: 18083

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18083

Exploit ID: 18084

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18084

Exploit ID: 18085

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18085

Exploit ID: 18151

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18151

Exploit ID: 18975

Source: exploitdb

URL: https://www.exploit-db.com/exploits/18975

Vulnerable Software (4)

Type: Configuration

Product: tinymce

Operating System: ubuntu hardy 8.04

Trait:
{  "unaffected": true}

Source: ubuntu

Type: Configuration

Vendor: *

Product: ajax_file_and_image_manager

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:phpletter:ajax_file_and_image_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "1.0",      "vulnerable": true    },    {      "cpe23uri"...

Source: nvd

Type: Configuration

Vendor: *

Product: phpmyfaq

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:phpletter:ajax_file_and_image_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "1.0",      "vulnerable": true    },    {      "cpe23uri"...

Source: nvd

Type: Configuration

Vendor: *

Product: tinymce

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:phpletter:ajax_file_and_image_manager:*:*:*:*:*:*:*:*",      "versionEndIncluding": "1.0",      "vulnerable": true    },    {      "cpe23uri"...

Source: nvd

End of list