CVE-2009-3181
Anantasoft Gazelle CMS 1.0 - Path Traversal and Arbitrary File Write via Customize Template Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3181. PoCs published by IHTeam.
AI-analyzed exploit summary This script exploits multiple vulnerabilities in Gazelle CMS 1.0, including RCE via file upload, LFI, and XSS. It uploads a malicious PHP file via a template customization feature and provides a shell interface for command execution.
Description
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.
Exploits (1)
This script exploits multiple vulnerabilities in Gazelle CMS 1.0, including RCE via file upload, LFI, and XSS. It uploads a malicious PHP file via a template customization feature and provides a shell interface for command execution.