CVE-2009-1230

Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
podcast_generatorpodcast_generator
𝑥
≤ 1.1
podcast_generatorpodcast_generator
0.6
podcast_generatorpodcast_generator
0.8
podcast_generatorpodcast_generator
0.9
podcast_generatorpodcast_generator
0.81
podcast_generatorpodcast_generator
0.91
podcast_generatorpodcast_generator
0.92
podcast_generatorpodcast_generator
0.93
podcast_generatorpodcast_generator
0.94
podcast_generatorpodcast_generator
0.95
podcast_generatorpodcast_generator
0.96
podcast_generatorpodcast_generator
0.96.2
podcast_generatorpodcast_generator
1.0
podcast_generatorpodcast_generator
1.0:beta_2
podcast_generatorpodcast_generator
1.0_beta:_beta
podcast_generatorpodcast_generator
1.0_beta2:_beta2
podcast_generatorpodcast_generator
1.0_beta3:_beta3
podcast_generatorpodcast_generator
1.0_beta4:_beta4
podcast_generatorpodcast_generator
1.0_beta4a:_beta4a
𝑥
= Vulnerable software versions