CVE-2009-3180
Anantasoft Gazelle CMS 1.0 - Unauthenticated Password Reset via User Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3180. PoCs published by IHTeam.
AI-analyzed exploit summary This script exploits multiple vulnerabilities in Gazelle CMS 1.0, including RCE via file upload, LFI, and XSS. It uploads a malicious PHP file via a template customization feature and provides a shell interface for command execution.
Description
Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by IHTeam · bashwebappsphp
https://www.exploit-db.com/exploits/9425
This script exploits multiple vulnerabilities in Gazelle CMS 1.0, including RCE via file upload, LFI, and XSS. It uploads a malicious PHP file via a template customization feature and provides a shell interface for command execution.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Gazelle CMS 1.0
No auth needed
Prerequisites:
magic_quotes_gpc Off · access to admin/settemplate.php
devstral-2 · analyzed Feb 18, 2026
Full analysis →
References (2)
Core 2
Core References
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/9425
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33686
Scores
EPSS
0.0209
EPSS Percentile
79.1%
Details
CWE
CWE-255
Status
published
Products (1)
anantasoft/gazelle_cms
1.0
Published
Sep 11, 2009
Tracked Since
Feb 18, 2026