CVE-2011-4825
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
- Phpletter Ajax File And Image Manager
- ≤ 1.0, 0.5, 0.5.5, 0.5.7, 0.6, 0.6.12, 0.7.8, 0.7.10, 0.8, 0.8.8, 0.8.9, 0.8.24, 0.9
- Phpmyfaq
- = 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9, 2.6.10, 2.6.11, 2.6.12, 2.6.13, 2.6.14, 2.6.15, 2.6.16, 2.6.17, 2.6.18, 2.7.0
- Tinymce
- ≤ 1.4.1
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 39.2% (98th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2011-12-15
CVE-2011-4825 at NVD
11 known exploits for CVE-2011-4825
Proof-of-concept code and exploit modules indexed by Sploitus
Log1 CMS 2.0 RCE
Log1 CMS writeInfo() PHP Code Injection
Log1 CMS writeInfo() PHP Code Injection
Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit)
Log1 CMS writeInfo() PHP Code Injection
phpMyFAQ 2.7.0 RCE
Log1 CMS 2.0 - 'ajax_create_folder.php' Remote Code Execution
PHPMyFAQ 2.7.0 - 'ajax_create_folder.php' Remote Code Execution
ZenPhoto 1.4.1.4 - 'ajax_create_folder.php' Remote Code Execution
aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
Ajax File and Image Manager 1.0 Final - Remote Code Execution