PoC Index

CVE-2011-4825

HIGH 7.5EPSS 39.2%

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
39.16% chance of exploitation in the next 30 days, 98th percentile
Published
2011-12-15
Updated
2024-09-17

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (6)

References

Related