{
    "id": "CVE-2011-4825",
    "published": "2011-12-15 03:57:34",
    "last_modified": "2026-06-16 23:35:28",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": "CWE-94",
    "description": "Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.",
    "epss_score": "0.39162",
    "epss_percentile": "0.98550",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:18:13",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "phpletter",
            "product": "ajax_file_and_image_manager"
        },
        {
            "vendor": "phpmyfaq",
            "product": "phpmyfaq"
        },
        {
            "vendor": "tinymce",
            "product": "tinymce"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "18975",
            "title": "Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit)",
            "date": "2012-06-03",
            "url": "https://www.exploit-db.com/exploits/18975"
        },
        {
            "source": "exploit-db",
            "ref_id": "18151",
            "title": "Log1 CMS 2.0 - 'ajax_create_folder.php' Remote Code Execution",
            "date": "2011-11-24",
            "url": "https://www.exploit-db.com/exploits/18151"
        },
        {
            "source": "exploit-db",
            "ref_id": "18083",
            "title": "ZenPhoto 1.4.1.4 - 'ajax_create_folder.php' Remote Code Execution",
            "date": "2011-11-05",
            "url": "https://www.exploit-db.com/exploits/18083"
        },
        {
            "source": "exploit-db",
            "ref_id": "18084",
            "title": "PHPMyFAQ 2.7.0 - 'ajax_create_folder.php' Remote Code Execution",
            "date": "2011-11-05",
            "url": "https://www.exploit-db.com/exploits/18084"
        },
        {
            "source": "exploit-db",
            "ref_id": "18085",
            "title": "aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution",
            "date": "2011-11-05",
            "url": "https://www.exploit-db.com/exploits/18085"
        },
        {
            "source": "exploit-db",
            "ref_id": "18075",
            "title": "Ajax File and Image Manager 1.0 Final - Remote Code Execution",
            "date": "2011-11-04",
            "url": "https://www.exploit-db.com/exploits/18075"
        }
    ],
    "refs_list": [
        "http://www.exploit-db.com/exploits/18075",
        "http://www.phpletter.com/en/DOWNLOAD/1/",
        "http://www.phpmyfaq.de/advisory_2011-10-25.php",
        "http://www.securityfocus.com/bid/50523",
        "http://www.zenphoto.org/trac/ticket/2005",
        "http://www.exploit-db.com/exploits/18075",
        "http://www.phpletter.com/en/DOWNLOAD/1/",
        "http://www.phpmyfaq.de/advisory_2011-10-25.php",
        "http://www.securityfocus.com/bid/50523",
        "http://www.zenphoto.org/trac/ticket/2005"
    ]
}