peter bassill · operator
$ cve CVE-2009-1230 JSON

CVE-2009-1230 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 1.8% (pctl 78)

Patch early

A public exploit exists.

Description

Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS1.79% — more likely to be exploited than 78% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-04-02
Last modified2026-06-16

Affected (1)

VendorProduct
podcast generatorpodcast generator

Public exploits

SourceTitleDate
exploit-dbPodcast Generator 1.1 - Remote Code Execution2009-03-31

References

→ the Explorer  ·  watch your stack  ·  NVD