CVE-2009-1230 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 1.8% (pctl 78)
Patch early
A public exploit exists.
Description
Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 1.79% — more likely to be exploited than 78% of all CVEs |
| Weakness | CWE-94 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-04-02 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| podcast generator | podcast generator |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Podcast Generator 1.1 - Remote Code Execution | 2009-03-31 |
→ the Explorer · watch your stack · NVD