Vulnerabilities
Vulnerable Software
Phpmyfaq:  >> Phpmyfaq  >> 2.6.13  Security Vulnerabilities
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6 before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows remote attackers to inject arbitrary PHP code into data.php via crafted parameters.
CVSS Score
7.5
EPSS Score
0.392
Published
2011-12-15
phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files.
CVSS Score
5.0
EPSS Score
0.012
Published
2011-09-24


Contact Us

Shodan ® - All rights reserved