PT-2006-6457 · Ariadne · Ariadne
Ajann
·
Published
2006-11-07
·
Updated
2024-08-07
·
CVE-2006-5776
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Ariadne version 2.4.1
Description:
The issue allows remote attackers to execute arbitrary PHP code via the
ariadne parameter in specific PHP files, including "ftp/loader.php" and "lib/includes/loader.cmd.php".Recommendations:
For Ariadne version 2.4.1, consider moving the affected files outside of the web document root and modify the
$ariadne variable in an include file as recommended by the installation instructions to mitigate the risk.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ariadne