phpMyFAQ Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2010-4558 - Vulnerability Database

phpMyFAQ Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2010-4558

High
Reference: CVE-2010-4558
Title: phpMyFAQ Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

phpMyFAQ 2.6.11 and 2.6.12 as distributed between December 4th and December 15th 2010 contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php which allows remote attackers to execute arbitrary PHP code.