CVE-2009-1230

Podcast Generator < 1.1 - Code Injection

Title source: rule

Description

Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.

Exploits (1)

exploitdb WORKING POC VERIFIED
by BlackHawk · phpwebappsphp
https://www.exploit-db.com/exploits/8324

Scores

EPSS 0.0241
EPSS Percentile 85.1%

Details

CWE
CWE-94
Status published
Products (18)
podcast_generator/podcast_generator 0.6
podcast_generator/podcast_generator 0.8
podcast_generator/podcast_generator 0.9
podcast_generator/podcast_generator 0.81
podcast_generator/podcast_generator 0.91
podcast_generator/podcast_generator 0.92
podcast_generator/podcast_generator 0.93
podcast_generator/podcast_generator 0.94
podcast_generator/podcast_generator 0.95
podcast_generator/podcast_generator 0.96
... and 8 more
Published Apr 02, 2009
Tracked Since Feb 18, 2026