peter bassill · operator
$ cve CVE-2011-4825 JSON

CVE-2011-4825 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 39.2% (pctl 99)

Patch early

A public exploit exists.

Description

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS39.16% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2011-12-15
Last modified2026-06-16

Affected (3)

VendorProduct
phpletterajax file and image manager
phpmyfaqphpmyfaq
tinymcetinymce

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD