Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-12-14 19:57
Updated : 2011-12-15 10:03
NVD link : CVE-2011-4825
Mitre link : CVE-2011-4825
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
tinymce
- tinymce
phpletter
- ajax_file_and_image_manager
phpmyfaq
- phpmyfaq