CVE
- Id
- 38661
- CVE No.
- CVE-2009-1226
- Status
- Candidate
- Description
- core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.
- Phase
- Assigned (20090402)
- Votes
- None (candidate not yet proposed)
- Comments