Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:13

Updated: 2022-10-03T16:15:13

Reserved: 2022-10-03T00:00:00


Link: CVE-2011-4825

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2011-12-15T03:57:34.667

Modified: 2011-12-15T18:03:31.667


Link: CVE-2011-4825

JSON object: View

cve-icon Redhat Information

No data.

CWE