CVE-2010-1927: Code Injection
Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when registerglobals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the pathom parameter to (1) bible.class.php, (2) dossier.class.php, (3) service.class.php, (4) collectivite.class.php, (5) droit.class.php, (6) tache.class.php, (7) emetteur.class.php, (8) utilisateur.class.php, (9) courrier.recherche.tab.class.php, and (10) profil.class.php in obj/. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1927?
The severity of CVE-2010-1927 is medium, with a score of 6.8.
How do I fix CVE-2010-1927?
To fix CVE-2010-1927, disable register_globals in your PHP configuration and update to a patched version of openMairie openCourrier.
What are the potential impacts of CVE-2010-1927?
CVE-2010-1927 may allow remote attackers to execute arbitrary PHP code, leading to possible data compromise or system takeover.
Which versions of openMairie openCourrier are affected by CVE-2010-1927?
CVE-2010-1927 affects openMairie openCourrier versions 2.02 and 2.03 beta.
What type of vulnerability is CVE-2010-1927 classified as?
CVE-2010-1927 is classified as a code injection vulnerability.