Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2011-12-15 03:57
Updated : 2024-02-04 17:54
NVD link : CVE-2011-4825
Mitre link : CVE-2011-4825
CVE.ORG link : CVE-2011-4825
JSON object : View
Products Affected
phpletter
- ajax_file_and_image_manager
tinymce
- tinymce
phpmyfaq
- phpmyfaq
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')