{ "schema_version": "1.4.0", "id": "GHSA-wrq6-29gg-753f", "modified": "2022-05-01T23:36:51Z", "published": "2022-05-01T23:36:51Z", "aliases": [ "CVE-2008-1124" ], "details": "Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absoluteurl parameter to (1) components/xmlparser/loadparser.php; (2) admin.php, (3) categories.php, (4) categories_add.php, (5) categories_remove.php, (6) edit.php, (7) editdel.php, (8) ftpfeature.php, (9) login.php, (10) pgRSSnews.php, (11) showcat.php, and (12) upload.php in core/admin/; and (13) archive_cat.php, (14) archive_nocat.php, and (15) recent_list.php in core/.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2008-1124" }, { "type": "WEB", "url": "https://www.exploit-db.com/exploits/5200" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/28038" } ], "database_specific": { "cwe_ids": [ "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2008-03-03T22:44:00Z" } }