Vulnerability Description
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3) categories.php, (4) categories_add.php, (5) categories_remove.php, (6) edit.php, (7) editdel.php, (8) ftpfeature.php, (9) login.php, (10) pgRSSnews.php, (11) showcat.php, and (12) upload.php in core/admin/; and (13) archive_cat.php, (14) archive_nocat.php, and (15) recent_list.php in core/.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Podcast Generator | Podcast Generator | <= 1.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/28038
- https://www.exploit-db.com/exploits/5200
- http://www.securityfocus.com/bid/28038
- https://www.exploit-db.com/exploits/5200
FAQ
What is CVE-2008-1124?
CVE-2008-1124 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) compon...
How severe is CVE-2008-1124?
CVE-2008-1124 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1124?
Check the references section above for vendor advisories and patch information. Affected products include: Podcast Generator Podcast Generator.