Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2009-3180

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.
0
Attacker Value
Unknown

CVE-2009-3181

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.
0
Attacker Value
Unknown

CVE-2009-3182

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in user/File/.
0
Attacker Value
Unknown

CVE-2009-3167

Disclosure Date: September 11, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
0