peter bassill · operator
$ cve CVE-2009-1226 JSON

CVE-2009-1226 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.35% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-04-02
Last modified2026-06-16

Affected (1)

VendorProduct
podcast generatorpodcast generator

Public exploits

SourceTitleDate
exploit-dbPodcast Generator 1.1 - Remote Code Execution2009-03-31

References

→ the Explorer  ·  watch your stack  ·  NVD