Ariadne CMS Remote Arbitrary Shell Command Injection Vulnerability
BID:28093
Info
Ariadne CMS Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 28093 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-7125 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Ariadne Ariadne CMS 2.4.1 Ariadne Ariadne CMS 2.4 Ariadne Ariadne CMS 0 |
| Not Vulnerable: |
Ariadne Ariadne CMS 2.6 |
Discussion
Ariadne CMS Remote Arbitrary Shell Command Injection Vulnerability
Ariadne CMS is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary shell commands in the context of the webserver hosting the vulnerable application. This may facilitate the remote compromise of affected computers.
This issue affects versions prior to Ariadne 2.6.
Ariadne CMS is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Attackers can exploit this issue to execute arbitrary shell commands in the context of the webserver hosting the vulnerable application. This may facilitate the remote compromise of affected computers.
This issue affects versions prior to Ariadne 2.6.
Exploit / POC
Ariadne CMS Remote Arbitrary Shell Command Injection Vulnerability
An attacker can use standard tools to exploit this issue.
An attacker can use standard tools to exploit this issue.
Solution / Fix
Ariadne CMS Remote Arbitrary Shell Command Injection Vulnerability
Solution:
The vendor has released an update that addresses this issue. Please see the references for more information.
Solution:
The vendor has released an update that addresses this issue. Please see the references for more information.
References
Ariadne CMS Remote Arbitrary Shell Command Injection Vulnerability
References:
References:
- Ariadne CMS Home Page (Ariadne)
- Changes in Ariadne since version Ariadne 2.4.1 (Ariadne)