Lucene search

K
cveMitreCVE-2009-1230
HistoryApr 02, 2009 - 3:30 p.m.

CVE-2009-1230

2009-04-0215:30:00
CWE-94
mitre
web.nvd.nist.gov
27
code injection
security vulnerability
podcast generator
php
remote authentication

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

54.2%

Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.

Affected configurations

Nvd
Node
podcast_generatorpodcast_generatorRange≀1.1
OR
podcast_generatorpodcast_generatorMatch0.6
OR
podcast_generatorpodcast_generatorMatch0.8
OR
podcast_generatorpodcast_generatorMatch0.9
OR
podcast_generatorpodcast_generatorMatch0.81
OR
podcast_generatorpodcast_generatorMatch0.91
OR
podcast_generatorpodcast_generatorMatch0.92
OR
podcast_generatorpodcast_generatorMatch0.93
OR
podcast_generatorpodcast_generatorMatch0.94
OR
podcast_generatorpodcast_generatorMatch0.95
OR
podcast_generatorpodcast_generatorMatch0.96
OR
podcast_generatorpodcast_generatorMatch0.96.2
OR
podcast_generatorpodcast_generatorMatch1.0
OR
podcast_generatorpodcast_generatorMatch1.0beta_2
OR
podcast_generatorpodcast_generatorMatch1.0_beta
OR
podcast_generatorpodcast_generatorMatch1.0_beta2
OR
podcast_generatorpodcast_generatorMatch1.0_beta3
OR
podcast_generatorpodcast_generatorMatch1.0_beta4
OR
podcast_generatorpodcast_generatorMatch1.0_beta4a
VendorProductVersionCPE
podcast_generatorpodcast_generator*cpe:2.3:a:podcast_generator:podcast_generator:*:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.6cpe:2.3:a:podcast_generator:podcast_generator:0.6:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.8cpe:2.3:a:podcast_generator:podcast_generator:0.8:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.9cpe:2.3:a:podcast_generator:podcast_generator:0.9:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.81cpe:2.3:a:podcast_generator:podcast_generator:0.81:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.91cpe:2.3:a:podcast_generator:podcast_generator:0.91:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.92cpe:2.3:a:podcast_generator:podcast_generator:0.92:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.93cpe:2.3:a:podcast_generator:podcast_generator:0.93:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.94cpe:2.3:a:podcast_generator:podcast_generator:0.94:*:*:*:*:*:*:*
podcast_generatorpodcast_generator0.95cpe:2.3:a:podcast_generator:podcast_generator:0.95:*:*:*:*:*:*:*
Rows per page:
1-10 of 191

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.002

Percentile

54.2%