CVE-2009-1226

core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:podcast_generator:podcast_generator:*:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.6:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.8:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.9:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.81:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.91:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.92:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.93:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.94:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.95:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.96:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:0.96.2:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0:beta_2:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0_beta:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0_beta2:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0_beta3:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0_beta4:*:*:*:*:*:*:*
cpe:2.3:a:podcast_generator:podcast_generator:1.0_beta4a:*:*:*:*:*:*:*

History

21 Nov 2024, 01:01

Type Values Removed Values Added
References () http://secunia.com/advisories/34555 - Vendor Advisory () http://secunia.com/advisories/34555 - Vendor Advisory
References () http://www.securityfocus.com/bid/34317 - Exploit () http://www.securityfocus.com/bid/34317 - Exploit
References () https://www.exploit-db.com/exploits/8324 - () https://www.exploit-db.com/exploits/8324 -

Information

Published : 2009-04-02 15:30

Updated : 2024-11-21 01:01


NVD link : CVE-2009-1226

Mitre link : CVE-2009-1226

CVE.ORG link : CVE-2009-1226


JSON object : View

Products Affected

podcast_generator

  • podcast_generator
CWE
CWE-264

Permissions, Privileges, and Access Controls