{"api_version":"1","generated_at":"2026-05-30T00:41:18+00:00","cve":"CVE-2011-4825","urls":{"html":"https://cve.report/CVE-2011-4825","api":"https://cve.report/api/cve/CVE-2011-4825.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-4825","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-4825"},"summary":{"title":"CVE-2011-4825","description":"Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-12-15 03:57:34","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.zenphoto.org/trac/ticket/2005","name":"http://www.zenphoto.org/trac/ticket/2005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#2005 (Remote Code Execution Vulnerability)\n     – zenphoto","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/50523","name":"http://www.securityfocus.com/bid/50523","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Ajax File and Image Manager 'data.php' PHP Code Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.exploit-db.com/exploits/18075","name":"http://www.exploit-db.com/exploits/18075","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ajax File and Image Manager v1.0 Final Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.phpmyfaq.de/advisory_2011-10-25.php","name":"http://www.phpmyfaq.de/advisory_2011-10-25.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"phpMyFAQ homepage - open source FAQ software | Security Advisory 2011-09-28","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.phpletter.com/en/DOWNLOAD/1/","name":"http://www.phpletter.com/en/DOWNLOAD/1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"DOWNLOAD","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-4825","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4825","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.5.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.5.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.6.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.7.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.7.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.8.24","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.8.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.8.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"0.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"beta1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"beta2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"rc2","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"rc3","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"rc4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"1.0","cpe7":"rc5","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpletter","cpe5":"ajax_file_and_image_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.11","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.12","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.14","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.15","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.16","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.17","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.18","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.6.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phpmyfaq","cpe5":"phpmyfaq","cpe6":"2.7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4825","vulnerable":"1","versionEndIncluding":"1.4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tinymce","cpe5":"tinymce","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:16:35.038Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.zenphoto.org/trac/ticket/2005"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.phpmyfaq.de/advisory_2011-10-25.php"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.phpletter.com/en/DOWNLOAD/1/"},{"name":"50523","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/50523"},{"name":"18075","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/18075"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-12-15T02:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.zenphoto.org/trac/ticket/2005"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.phpmyfaq.de/advisory_2011-10-25.php"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.phpletter.com/en/DOWNLOAD/1/"},{"name":"50523","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/50523"},{"name":"18075","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/18075"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-4825","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.zenphoto.org/trac/ticket/2005","refsource":"CONFIRM","url":"http://www.zenphoto.org/trac/ticket/2005"},{"name":"http://www.phpmyfaq.de/advisory_2011-10-25.php","refsource":"CONFIRM","url":"http://www.phpmyfaq.de/advisory_2011-10-25.php"},{"name":"http://www.phpletter.com/en/DOWNLOAD/1/","refsource":"CONFIRM","url":"http://www.phpletter.com/en/DOWNLOAD/1/"},{"name":"50523","refsource":"BID","url":"http://www.securityfocus.com/bid/50523"},{"name":"18075","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/18075"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-4825","datePublished":"2011-12-15T02:00:00.000Z","dateReserved":"2011-12-14T00:00:00.000Z","dateUpdated":"2024-09-17T00:46:26.904Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-12-15 03:57:34","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0","matchCriteriaId":"1A288447-ABFD-4DF0-A958-439142DD7890"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.5:*:*:*:*:*:*:*","matchCriteriaId":"C44AC58F-94E3-4301-944E-E91C8E475CAA"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.5.5:*:*:*:*:*:*:*","matchCriteriaId":"2E61F309-FB2A-47BC-B43E-BE8DA726955C"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.5.7:*:*:*:*:*:*:*","matchCriteriaId":"383D3577-4F74-4842-8ADD-A6B9BEB410E7"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.6:*:*:*:*:*:*:*","matchCriteriaId":"397A3DA9-99D3-41A0-8605-FFE1360147B0"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.6.12:*:*:*:*:*:*:*","matchCriteriaId":"2B27F427-D46B-4B81-ADE7-81DAC498B450"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.7.8:*:*:*:*:*:*:*","matchCriteriaId":"3870AF03-C6E5-4F49-A502-2091A5017519"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.7.10:*:*:*:*:*:*:*","matchCriteriaId":"BBB959F7-7F97-4ECE-8FF1-843E73222935"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.8:*:*:*:*:*:*:*","matchCriteriaId":"70400ECC-7102-4984-8804-2F0A18A07617"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.8.8:*:*:*:*:*:*:*","matchCriteriaId":"691C193F-C1E5-44C0-953A-C6D6DE4C4FD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.8.9:*:*:*:*:*:*:*","matchCriteriaId":"CAFDC1AD-A611-40DA-85EA-517BE8187F29"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.8.24:*:*:*:*:*:*:*","matchCriteriaId":"8793289D-65A5-4DC0-8AD7-132042F293B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:0.9:*:*:*:*:*:*:*","matchCriteriaId":"0DE10AD9-E5BD-4A25-92D2-4369EF15BD41"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:beta1:*:*:*:*:*:*","matchCriteriaId":"FDBDAC0F-BABF-48F2-B6CE-E3FCC740A45F"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:beta2:*:*:*:*:*:*","matchCriteriaId":"9013E5FA-CFD9-430D-BDA7-2C19263C95F7"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:rc1:*:*:*:*:*:*","matchCriteriaId":"AAC0C8B9-243E-4958-8558-AB49BBDCE551"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:rc2:*:*:*:*:*:*","matchCriteriaId":"DA18AF75-D2E6-4020-9F02-39AE96166129"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:rc3:*:*:*:*:*:*","matchCriteriaId":"64671966-303B-4B58-A5B9-7676AB132E17"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:rc4:*:*:*:*:*:*","matchCriteriaId":"659FCBE0-F0ED-443F-853E-6A14F70895FC"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpletter:ajax_file_and_image_manager:1.0:rc5:*:*:*:*:*:*","matchCriteriaId":"894CE3C2-3E2D-45CA-92F0-643A8A8CC8CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.0:*:*:*:*:*:*:*","matchCriteriaId":"726107EB-E267-4B1D-93B9-A0256B243800"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.1:*:*:*:*:*:*:*","matchCriteriaId":"1A6B01EF-B80C-4F4A-99F5-0BC54403A1A0"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.2:*:*:*:*:*:*:*","matchCriteriaId":"448588AE-7FF3-423F-A687-E72A5720D914"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.3:*:*:*:*:*:*:*","matchCriteriaId":"70E8566E-13D8-401E-B6C6-4A36532D4018"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.4:*:*:*:*:*:*:*","matchCriteriaId":"AE0E5995-E11D-4430-BB21-29A3CA9A9304"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.5:*:*:*:*:*:*:*","matchCriteriaId":"F0235BFA-8604-417C-96E5-D0A3CA36AF93"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.6:*:*:*:*:*:*:*","matchCriteriaId":"5A3613B8-2D02-4517-8B90-D382B3731D3E"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.7:*:*:*:*:*:*:*","matchCriteriaId":"38292B44-CA69-4ADE-A93F-A4609E0B75E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.8:*:*:*:*:*:*:*","matchCriteriaId":"2DC00325-D9B4-4219-A63F-04EEB7DA6F6E"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.9:*:*:*:*:*:*:*","matchCriteriaId":"714DA52A-6AE0-41A7-9250-08BE3B336C71"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.10:*:*:*:*:*:*:*","matchCriteriaId":"17526059-D468-4AE3-A24E-8B4FDD26915E"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.11:*:*:*:*:*:*:*","matchCriteriaId":"D2EA6480-F5BB-4513-8D25-78E185BAAB8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.12:*:*:*:*:*:*:*","matchCriteriaId":"86B54292-AAFE-42BC-B164-97368B1D006A"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.13:*:*:*:*:*:*:*","matchCriteriaId":"74981F3E-EADC-46F2-A0D4-4FFA6C87A391"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.14:*:*:*:*:*:*:*","matchCriteriaId":"21162859-A1AB-4477-BA1B-4A2C2DB4705D"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.15:*:*:*:*:*:*:*","matchCriteriaId":"06AC9151-E197-479F-B1BA-CAEEFC488EDE"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.16:*:*:*:*:*:*:*","matchCriteriaId":"21ABBD7C-7FC6-48A1-88CE-282156EB5B7C"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.17:*:*:*:*:*:*:*","matchCriteriaId":"092575EA-2318-4FDD-9EE0-D5AFC5A14854"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.6.18:*:*:*:*:*:*:*","matchCriteriaId":"F971EC18-895D-469E-9D69-94D13017B62C"},{"vulnerable":true,"criteria":"cpe:2.3:a:phpmyfaq:phpmyfaq:2.7.0:*:*:*:*:*:*:*","matchCriteriaId":"9650943E-4BB2-4A0D-B3D5-07B99566A705"},{"vulnerable":true,"criteria":"cpe:2.3:a:tinymce:tinymce:*:*:*:*:*:*:*:*","versionEndIncluding":"1.4.1","matchCriteriaId":"F9B9DC89-26A9-42B3-A037-26A5B3E3441B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"4825","Ordinal":"1","Title":"CVE-2011-4825","CVE":"CVE-2011-4825","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"4825","Ordinal":"1","NoteData":"Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.","Type":"Description","Title":"CVE-2011-4825"},{"CveYear":"2011","CveId":"4825","Ordinal":"2","NoteData":"2011-12-14","Type":"Other","Title":"Published"}]}}}