ReloadCMS versions less than 1.2.5 do not properly sanitize the user-agent request header before storing in stats.dat leading to XSS when the admin views the site statistics. Permissions can be escalated further ones logged in as admin.
191369e980daf69a88a2bc929a6f7b30484c78f2eb5396c3405bc91a8954e92b