First published: Tue Nov 07 2006(Updated: )
** DISPUTED ** Multiple PHP remote file inclusions in Ariadne 2.4.1 allows remote attackers to execute arbitrary PHP code via the ariadne parameter in (1) ftp/loader.php and (2) lib/includes/loader.cmd.php. NOTE: this issue is disputed by CVE, since installation instructions recommend that the files be placed outside of the web document root and require the administrator to modify $ariadne in an include file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ariadne CMS | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-5776 is debated, as it involves multiple remote file inclusion vulnerabilities in Ariadne 2.4.1.
To fix CVE-2006-5776, ensure proper validation of the 'ariadne' parameter and consider restricting access to affected files.
Ariadne CMS version 2.4.1 is affected by CVE-2006-5776.
Yes, CVE-2006-5776 allows remote attackers to execute arbitrary PHP code due to file inclusion vulnerabilities.
The exploitation of CVE-2006-5776 is not well-documented, but it remains a potential risk for users of the affected software.