PT-2010-3568 · Openmairie · Openmairie Openregistrecil

Cr4Wl3R

·

Published

2010-05-18

·

Updated

2010-05-19

·

CVE-2010-1947

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions openMairie Openregistrecil version 1.02
Description A directory traversal issue exists in the scr/soustab.php file of openMairie Openregistrecil. When register globals is enabled, remote attackers can include and execute arbitrary local files by using directory traversal sequences in the dsn[phptype] parameter.
Recommendations For openMairie Openregistrecil version 1.02, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the scr/soustab.php file and avoid using the dsn[phptype] parameter with untrusted input until a fix is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1947

Affected Products

Openmairie Openregistrecil