First published: Fri Dec 17 2010(Updated: )
phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php, which allows remote attackers to execute arbitrary PHP code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpMyFAQ | =2.6.11 | |
phpMyFAQ | =2.6.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4558 is classified as a critical vulnerability due to its potential for arbitrary code execution.
To fix CVE-2010-4558, you should upgrade to a patched version of phpMyFAQ that is not affected by this vulnerability.
CVE-2010-4558 affects users of phpMyFAQ versions 2.6.11 and 2.6.12.
CVE-2010-4558 enables remote attackers to execute arbitrary PHP code through the compromised getTopTen method.
CVE-2010-4558 was introduced in phpMyFAQ versions 2.6.11 and 2.6.12, distributed between December 4th and December 15th, 2010.