vendor:
Gazelle CMS
by:
RoMaNcYxHaCkEr
7,5
CVSS
HIGH
Remote Arbitrary File Upload
264
CWE
Product Name: Gazelle CMS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:anantasoft:gazelle_cms:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Gazelle CMS 1.0 Remote Arbitrary File Upload Vuln
Gazelle CMS 1.0 is vulnerable to a remote arbitrary file upload vulnerability. An attacker can exploit this vulnerability by sending a malicious file to the vulnerable server and then accessing it via a web browser. This can be done by changing the 'Type' parameter in the URL from 'Image' to 'File' and then uploading the malicious file. The malicious file can then be accessed via the URL http://localhost/Ananta_Gazelle1.0/user/File/shell.php
Mitigation:
The vendor has not released a patch for this vulnerability. It is recommended to disable the file upload feature or restrict access to the vulnerable URL.