CVE Vulnerabilities

CVE-2009-1226

Published: Apr 02, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.

Affected Software

NameVendorStart VersionEnd Version
Podcast_generatorPodcast_generator*1.1 (including)
Podcast_generatorPodcast_generator0.6 (including)0.6 (including)
Podcast_generatorPodcast_generator0.8 (including)0.8 (including)
Podcast_generatorPodcast_generator0.9 (including)0.9 (including)
Podcast_generatorPodcast_generator0.81 (including)0.81 (including)
Podcast_generatorPodcast_generator0.91 (including)0.91 (including)
Podcast_generatorPodcast_generator0.92 (including)0.92 (including)
Podcast_generatorPodcast_generator0.93 (including)0.93 (including)
Podcast_generatorPodcast_generator0.94 (including)0.94 (including)
Podcast_generatorPodcast_generator0.95 (including)0.95 (including)
Podcast_generatorPodcast_generator0.96 (including)0.96 (including)
Podcast_generatorPodcast_generator0.96.2 (including)0.96.2 (including)
Podcast_generatorPodcast_generator1.0 (including)1.0 (including)
Podcast_generatorPodcast_generator1.0-beta_2 (including)1.0-beta_2 (including)
Podcast_generatorPodcast_generator1.0_beta (including)1.0_beta (including)
Podcast_generatorPodcast_generator1.0_beta2 (including)1.0_beta2 (including)
Podcast_generatorPodcast_generator1.0_beta3 (including)1.0_beta3 (including)
Podcast_generatorPodcast_generator1.0_beta4 (including)1.0_beta4 (including)
Podcast_generatorPodcast_generator1.0_beta4a (including)1.0_beta4a (including)

References