CVE-2009-3182
Anantasoft Gazelle CMS 1.0 - Unauthenticated Arbitrary File Upload via File Manager
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-3182. PoCs published by RoMaNcYxHaCkEr, IHTeam.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Gazelle CMS 1.0 by manipulating the 'Type' parameter in the file manager's connector script to upload a malicious PHP shell.
Description
Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in user/File/.
Exploits (2)
This exploit demonstrates an arbitrary file upload vulnerability in Gazelle CMS 1.0 by manipulating the 'Type' parameter in the file manager's connector script to upload a malicious PHP shell.
This script exploits multiple vulnerabilities in Gazelle CMS 1.0, including RCE via file upload, LFI, and XSS. It uploads a malicious PHP file via a template customization feature and provides a shell interface for command execution.