CVE-2005-1181

Ariadne CMS 2.4 - Remote Code Execution via Ariadne Parameter Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-1181. PoCs published by Fidel Costa.

AI-analyzed exploit summary This exploit targets a remote file inclusion vulnerability in Ariadne CMS 2.4 by injecting a malicious URL into the 'ariadne' parameter of loader.php, allowing arbitrary server-side script execution. The PoC uses a Perl script to send HTTP requests with attacker-controlled input to achieve remote command execution.

Description

NOTE: this issue has been disputed by the vendor. PHP remote code injection vulnerability in loader.php for Ariadne CMS 2.4 allows remote attackers to execute arbitrary PHP code by modifying the ariadne parameter to reference a URL on a remote web server that contains the code. NOTE: the vendor has disputed this issue, saying that loader.php first requires the "ariadne.inc" file, which defines the $ariadne variable, and thus it cannot be modified by an attacker. In addition, CVE personnel have partially verified the dispute via source code inspection of Ariadne 2.4 as available on July 5, 2005

Exploits (1)

exploitdb WORKING POC VERIFIED
by Fidel Costa · perlwebappsphp
https://www.exploit-db.com/exploits/25431

This exploit targets a remote file inclusion vulnerability in Ariadne CMS 2.4 by injecting a malicious URL into the 'ariadne' parameter of loader.php, allowing arbitrary server-side script execution. The PoC uses a Perl script to send HTTP requests with attacker-controlled input to achieve remote command execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Ariadne CMS 2.4
No auth needed
Prerequisites: Network access to the target web server · Ariadne CMS 2.4 installed with vulnerable files (loader.php, setlink.php, view.php) · Ability to host a malicious script on an attacker-controlled server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/15549
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1013721
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/20611

Scores

EPSS 0.0252
EPSS Percentile 82.8%

Details

Status published
Products (1)
ariadne/ariadne_cms 2.4
Published May 02, 2005
Tracked Since Feb 18, 2026