CVE-2011-4825
HIGH 7.5EPSS 39.2%
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 39.16% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2011-12-15
- Updated
- 2024-09-17
Proof-of-concept exploits (1)
Metasploit modules (1)
ExploitDB entries (6)
- https://www.exploit-db.com/exploits/18975
- https://www.exploit-db.com/exploits/18085
- https://www.exploit-db.com/exploits/18084
- https://www.exploit-db.com/exploits/18083
- https://www.exploit-db.com/exploits/18075
- https://www.exploit-db.com/exploits/18151