PT-2006-6457 · Ariadne · Ariadne

·

CVE-2006-5776

·

Published

2006-11-07

·

Updated

2024-08-07

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Ariadne version 2.4.1
Description: The issue allows remote attackers to execute arbitrary PHP code via the ariadne parameter in specific PHP files, including "ftp/loader.php" and "lib/includes/loader.cmd.php".
Recommendations: For Ariadne version 2.4.1, consider moving the affected files outside of the web document root and modify the $ariadne variable in an include file as recommended by the installation instructions to mitigate the risk.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5776

Affected Products

Ariadne