CVE-2009-1230

podcast_generator <= 1.1 - Authenticated PHP Code Injection via Recent Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-1230. PoCs published by BlackHawk.

AI-analyzed exploit summary This exploit targets Podcast Generator <= 1.1 by deleting the config file and reconfiguring it with malicious code to achieve remote code execution. It leverages unauthenticated file deletion and unsanitized input in the configuration script.

Description

Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by BlackHawk · phpwebappsphp
https://www.exploit-db.com/exploits/8324

This exploit targets Podcast Generator <= 1.1 by deleting the config file and reconfiguring it with malicious code to achieve remote code execution. It leverages unauthenticated file deletion and unsanitized input in the configuration script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Podcast Generator <= 1.1
No auth needed
Prerequisites: Network access to the target · Podcast Generator <= 1.1 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8324

Scores

EPSS 0.0179
EPSS Percentile 75.5%

Details

CWE
CWE-94
Status published
Products (18)
podcast_generator/podcast_generator 0.6
podcast_generator/podcast_generator 0.8
podcast_generator/podcast_generator 0.9
podcast_generator/podcast_generator 0.81
podcast_generator/podcast_generator 0.91
podcast_generator/podcast_generator 0.92
podcast_generator/podcast_generator 0.93
podcast_generator/podcast_generator 0.94
podcast_generator/podcast_generator 0.95
podcast_generator/podcast_generator 0.96
... and 8 more
Published Apr 02, 2009
Tracked Since Feb 18, 2026