CVE-2011-4825
Summary
| CVE | CVE-2011-4825 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-12-15 03:57:34 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Phpletter | Ajax File And Image Manager | 0.5 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.5.5 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.5.7 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.6 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.6.12 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.7.10 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.7.8 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.8 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.8.24 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.8.8 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.8.9 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 0.9 | All | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | beta1 | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | beta2 | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | rc1 | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | rc2 | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | rc3 | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | rc4 | All | All |
| Application | Phpletter | Ajax File And Image Manager | 1.0 | rc5 | All | All |
| Application | Phpletter | Ajax File And Image Manager | All | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.0 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.1 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.10 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.11 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.12 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.13 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.14 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.15 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.16 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.17 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.18 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.2 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.3 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.4 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.5 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.6 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.7 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.8 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.6.9 | All | All | All |
| Application | Phpmyfaq | Phpmyfaq | 2.7.0 | All | All | All |
| Application | Tinymce | Tinymce | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| #2005 (Remote Code Execution Vulnerability) – zenphoto | af854a3a-2127-422b-91ae-364da2661108 | www.zenphoto.org | |
| Ajax File and Image Manager 'data.php' PHP Code Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit |
| Ajax File and Image Manager v1.0 Final Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| phpMyFAQ homepage - open source FAQ software | Security Advisory 2011-09-28 | af854a3a-2127-422b-91ae-364da2661108 | www.phpmyfaq.de | |
| DOWNLOAD | af854a3a-2127-422b-91ae-364da2661108 | www.phpletter.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.