First published: Thu Dec 15 2011(Updated: )
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
phpletter Ajax File and Image Manager | =1.0-rc4 | |
phpMyFAQ | =2.6.4 | |
TinyMCE | <=1.4.1 | |
phpletter Ajax File and Image Manager | =0.8.8 | |
phpMyFAQ | =2.6.14 | |
phpletter Ajax File and Image Manager | =0.7.8 | |
phpMyFAQ | =2.6.5 | |
phpMyFAQ | =2.6.2 | |
phpletter Ajax File and Image Manager | =0.8.9 | |
phpMyFAQ | =2.6.16 | |
phpMyFAQ | =2.6.7 | |
phpMyFAQ | =2.7.0 | |
phpletter Ajax File and Image Manager | =1.0-rc5 | |
phpletter Ajax File and Image Manager | =0.7.10 | |
phpletter Ajax File and Image Manager | =0.5 | |
phpletter Ajax File and Image Manager | =0.8 | |
phpletter Ajax File and Image Manager | =0.6.12 | |
phpMyFAQ | =2.6.13 | |
phpMyFAQ | =2.6.9 | |
phpletter Ajax File and Image Manager | =1.0-beta2 | |
phpMyFAQ | =2.6.1 | |
phpletter Ajax File and Image Manager | =0.8.24 | |
phpMyFAQ | =2.6.17 | |
phpletter Ajax File and Image Manager | <=1.0 | |
phpletter Ajax File and Image Manager | =1.0-beta1 | |
phpletter Ajax File and Image Manager | =1.0-rc2 | |
phpMyFAQ | =2.6.10 | |
phpletter Ajax File and Image Manager | =1.0-rc3 | |
phpletter Ajax File and Image Manager | =0.5.7 | |
phpletter Ajax File and Image Manager | =1.0-rc1 | |
phpMyFAQ | =2.6.11 | |
phpMyFAQ | =2.6.8 | |
phpletter Ajax File and Image Manager | =0.5.5 | |
phpMyFAQ | =2.6.3 | |
phpMyFAQ | =2.6.0 | |
phpletter Ajax File and Image Manager | =0.6 | |
phpMyFAQ | =2.6.18 | |
phpMyFAQ | =2.6.12 | |
phpMyFAQ | =2.6.6 | |
phpMyFAQ | =2.6.15 | |
phpletter Ajax File and Image Manager | =0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4825 has a moderate severity allowing for arbitrary PHP code injection.
To fix CVE-2011-4825, upgrade to the patched versions of Ajax File and Image Manager or phpMyFAQ specified in the advisory.
CVE-2011-4825 affects Ajax File and Image Manager versions prior to 1.1, and specific versions of TinyMCE and phpMyFAQ.
Yes, CVE-2011-4825 can be exploited remotely by attackers to inject arbitrary PHP code.
While there may be discussions about the vulnerability, it is advised to check security forums and advisories for details rather than look for specific public exploits.