phpMyFAQ 2.6.11 and 2.6.12, as distributed between December 4th and December 15th 2010, contains an externally introduced modification (Trojan Horse) in the getTopTen method in inc/Faq.php, which allows remote attackers to execute arbitrary PHP code.
| Software | From | Fixed in |
|---|---|---|
phpmyfaq / phpmyfaq
|
2.6.11 | 2.6.11.x |
phpmyfaq / phpmyfaq
|
2.6.12 | 2.6.12.x |