CVE-2010-1920: Path Traversal
Published May 12, 2010
·Updated
Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Affected Software
1 affected component
openMairie openAnnuaire=2.00
Event History
May 12, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1920?
The severity of CVE-2010-1920 is medium with a score of 6.8.
2
What type of vulnerability is CVE-2010-1920?
CVE-2010-1920 is a directory traversal vulnerability.
3
How can I mitigate CVE-2010-1920?
To mitigate CVE-2010-1920, disable register_globals in your PHP configuration and validate user input to prevent directory traversal.
4
What versions of openMairie openAnnuaire are affected by CVE-2010-1920?
CVE-2010-1920 affects OpenMairie openAnnuaire version 2.00.
5
Can CVE-2010-1920 lead to remote code execution?
Yes, CVE-2010-1920 allows remote attackers to execute arbitrary local files, potentially leading to remote code execution.