CVE-2009-1226
02.04.2009, 15:30
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.Enginsight
Vendor | Product | Version |
---|---|---|
podcast_generator | podcast_generator | 𝑥 ≤ 1.1 |
podcast_generator | podcast_generator | 0.6 |
podcast_generator | podcast_generator | 0.8 |
podcast_generator | podcast_generator | 0.9 |
podcast_generator | podcast_generator | 0.81 |
podcast_generator | podcast_generator | 0.91 |
podcast_generator | podcast_generator | 0.92 |
podcast_generator | podcast_generator | 0.93 |
podcast_generator | podcast_generator | 0.94 |
podcast_generator | podcast_generator | 0.95 |
podcast_generator | podcast_generator | 0.96 |
podcast_generator | podcast_generator | 0.96.2 |
podcast_generator | podcast_generator | 1.0 |
podcast_generator | podcast_generator | 1.0:beta_2 |
podcast_generator | podcast_generator | 1.0_beta:_beta |
podcast_generator | podcast_generator | 1.0_beta2:_beta2 |
podcast_generator | podcast_generator | 1.0_beta3:_beta3 |
podcast_generator | podcast_generator | 1.0_beta4:_beta4 |
podcast_generator | podcast_generator | 1.0_beta4a:_beta4a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration