---
title: "CVE-2011-4825\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-4825?format=md
keywords: index, follow
---

# CVE-2011-4825

Publication date 15 December 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Static code injection vulnerability in inc/function.base.php in Ajax File
and Image Manager before 1.1, as used in tinymce before 1.4.2, phpMyFAQ 2.6
before 2.6.19 and 2.7 before 2.7.1, and possibly other products, allows
remote attackers to inject arbitrary PHP code into data.php via crafted
parameters.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tinymce | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |
| tinymce2 | 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4825)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-4825)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-4825)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-4825)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-4825>
