Lucene search

K
cve[email protected]CVE-2011-4825
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2011-4825

2022-10-0316:15:13
CWE-94
web.nvd.nist.gov
40
cve-2011-4825
static code injection
ajax file and image manager
tinymce
phpmyfaq
vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.969 High

EPSS

Percentile

99.7%

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

Affected configurations

NVD
Node
phpletterajax_file_and_image_managerRange1.0
OR
phpletterajax_file_and_image_managerMatch0.5
OR
phpletterajax_file_and_image_managerMatch0.5.5
OR
phpletterajax_file_and_image_managerMatch0.5.7
OR
phpletterajax_file_and_image_managerMatch0.6
OR
phpletterajax_file_and_image_managerMatch0.6.12
OR
phpletterajax_file_and_image_managerMatch0.7.8
OR
phpletterajax_file_and_image_managerMatch0.7.10
OR
phpletterajax_file_and_image_managerMatch0.8
OR
phpletterajax_file_and_image_managerMatch0.8.8
OR
phpletterajax_file_and_image_managerMatch0.8.9
OR
phpletterajax_file_and_image_managerMatch0.8.24
OR
phpletterajax_file_and_image_managerMatch0.9
OR
phpletterajax_file_and_image_managerMatch1.0beta1
OR
phpletterajax_file_and_image_managerMatch1.0beta2
OR
phpletterajax_file_and_image_managerMatch1.0rc1
OR
phpletterajax_file_and_image_managerMatch1.0rc2
OR
phpletterajax_file_and_image_managerMatch1.0rc3
OR
phpletterajax_file_and_image_managerMatch1.0rc4
OR
phpletterajax_file_and_image_managerMatch1.0rc5
OR
phpmyfaqphpmyfaqMatch2.6.0
OR
phpmyfaqphpmyfaqMatch2.6.1
OR
phpmyfaqphpmyfaqMatch2.6.2
OR
phpmyfaqphpmyfaqMatch2.6.3
OR
phpmyfaqphpmyfaqMatch2.6.4
OR
phpmyfaqphpmyfaqMatch2.6.5
OR
phpmyfaqphpmyfaqMatch2.6.6
OR
phpmyfaqphpmyfaqMatch2.6.7
OR
phpmyfaqphpmyfaqMatch2.6.8
OR
phpmyfaqphpmyfaqMatch2.6.9
OR
phpmyfaqphpmyfaqMatch2.6.10
OR
phpmyfaqphpmyfaqMatch2.6.11
OR
phpmyfaqphpmyfaqMatch2.6.12
OR
phpmyfaqphpmyfaqMatch2.6.13
OR
phpmyfaqphpmyfaqMatch2.6.14
OR
phpmyfaqphpmyfaqMatch2.6.15
OR
phpmyfaqphpmyfaqMatch2.6.16
OR
phpmyfaqphpmyfaqMatch2.6.17
OR
phpmyfaqphpmyfaqMatch2.6.18
OR
phpmyfaqphpmyfaqMatch2.7.0
OR
tinymcetinymceRange1.4.1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.3 High

AI Score

Confidence

Low

0.969 High

EPSS

Percentile

99.7%