PT-2005-2197 · Ariadne · Ariadne Cms
Published
2005-04-19
·
Updated
2024-08-07
·
CVE-2005-1181
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ariadne CMS version 2.4
Description
The issue concerns a PHP remote code injection vulnerability in loader.php, allegedly allowing remote attackers to execute arbitrary PHP code by modifying the
ariadne parameter to reference a URL on a remote web server that contains the code. However, the vendor has disputed this issue, stating that loader.php first requires the "ariadne.inc" file, which defines the $ariadne variable, making it impossible for an attacker to modify. CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ariadne Cms