CVE-2010-1926: Path Traversal
Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1926?
The severity of CVE-2010-1926 is rated medium with a score of 6.8.
How do I fix CVE-2010-1926?
To fix CVE-2010-1926, disable register_globals and ensure proper input validation in the application.
What is the impact of CVE-2010-1926?
CVE-2010-1926 can allow remote attackers to include and execute arbitrary local files on the server.
Which versions of openMairie openCourrier are affected by CVE-2010-1926?
Versions 2.02 and 2.03 beta of openMairie openCourrier are affected by CVE-2010-1926.
What type of vulnerability is CVE-2010-1926 classified as?
CVE-2010-1926 is classified as a Directory Traversal vulnerability.