Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
NOTE: this issue has been disputed by the vendor. PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers to execute arbitrary PHP code by modifying the ariadne parameter to reference a URL on a remote web server that contains the code. NOTE: the vendor has disputed this issue, saying that loader.php first requires the "ariadne.inc" file, which defines the $ariadne variable, and thus it cannot be modified by an attacker. In addition, CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4 as available on July 5, 2005
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ariadne CMS 2.4的loader.php PHP远程代码注入漏洞
Vulnerability Description
Ariadne CMS 2.4的loader.php中存在PHP远程代码注入漏洞,远程攻击者可以通过修改ariadne参数以引用一个远程web服务器上含有该代码的URL,从而执行任意PHP代码。注:厂商对此提出争议,指出loader.php先请求"ariadne.inc"文件,该文件定义$ariadne变量,因此攻击者不能修改它。
CVSS Information
N/A
Vulnerability Type
N/A