CVE

Id
38661  
CVE No.
CVE-2009-1226  
Status
Candidate  
Description
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.  
Phase
Assigned (20090402)  
Votes
None (candidate not yet proposed)  
Comments