core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Podcast_generator | Podcast_generator | * | 1.1 (including) |
Podcast_generator | Podcast_generator | 0.6 (including) | 0.6 (including) |
Podcast_generator | Podcast_generator | 0.8 (including) | 0.8 (including) |
Podcast_generator | Podcast_generator | 0.9 (including) | 0.9 (including) |
Podcast_generator | Podcast_generator | 0.81 (including) | 0.81 (including) |
Podcast_generator | Podcast_generator | 0.91 (including) | 0.91 (including) |
Podcast_generator | Podcast_generator | 0.92 (including) | 0.92 (including) |
Podcast_generator | Podcast_generator | 0.93 (including) | 0.93 (including) |
Podcast_generator | Podcast_generator | 0.94 (including) | 0.94 (including) |
Podcast_generator | Podcast_generator | 0.95 (including) | 0.95 (including) |
Podcast_generator | Podcast_generator | 0.96 (including) | 0.96 (including) |
Podcast_generator | Podcast_generator | 0.96.2 (including) | 0.96.2 (including) |
Podcast_generator | Podcast_generator | 1.0 (including) | 1.0 (including) |
Podcast_generator | Podcast_generator | 1.0-beta_2 (including) | 1.0-beta_2 (including) |
Podcast_generator | Podcast_generator | 1.0_beta (including) | 1.0_beta (including) |
Podcast_generator | Podcast_generator | 1.0_beta2 (including) | 1.0_beta2 (including) |
Podcast_generator | Podcast_generator | 1.0_beta3 (including) | 1.0_beta3 (including) |
Podcast_generator | Podcast_generator | 1.0_beta4 (including) | 1.0_beta4 (including) |
Podcast_generator | Podcast_generator | 1.0_beta4a (including) | 1.0_beta4a (including) |