📦

ajax_file_and_image_manager

Vendor: phpletter

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 1 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 39.16% Exploit Prob.
Latest CVE CVE-2011-4825 Dec 15

Security Vulnerability Index

Page 1 / 1
7.5 CVSS
CVE-2011-4825
RCE Exploit Found

Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.

EPSS: 39.16%