Gazelle CMS 1.0 Multiple Vulnerabilities
Gazelle CMS 1.0 is vulnerable to multiple vulnerabilities such as Password Reset, Local File Inclusion, Cross-Site Scripting and Remote Code Execution. The Password Reset vulnerability allows an attacker to reset the password of any user by sending a crafted request to the renew.php file. The Local File Inclusion vulnerability allows an attacker to include a remote file by sending a crafted request to the index.php file. The Cross-Site Scripting vulnerability allows an attacker to inject malicious JavaScript code by sending a crafted request to the user.php and search.php files. The Remote Code Execution vulnerability allows an attacker to execute arbitrary code on the server by sending a crafted request to the settemplate.php file.