CVE-2010-1928: Path Traversal
Published May 12, 2010
·Updated
Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Affected Software
1 affected component
openMairie openPlanning=1.00
Event History
May 12, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1928?
CVE-2010-1928 has a medium severity rating of 6.8.
2
How do I fix CVE-2010-1928?
To fix CVE-2010-1928, disable register_globals and ensure proper input validation on the dsn[phptype] parameter.
3
What software is affected by CVE-2010-1928?
CVE-2010-1928 affects openMairie openPlanning version 1.00.
4
What type of vulnerability is CVE-2010-1928?
CVE-2010-1928 is classified as a directory traversal vulnerability.
5
What can attackers do with CVE-2010-1928?
Attackers can exploit CVE-2010-1928 to include and execute arbitrary local files on the affected system.