CVE-2010-1935: Path Traversal
Published May 12, 2010
·Updated
Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Affected Software
1 affected component
openMairie Openpresse=1.01
Event History
May 12, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1935?
CVE-2010-1935 has a medium severity rating of 6.8.
2
What type of vulnerability is identified by CVE-2010-1935?
CVE-2010-1935 is a directory traversal vulnerability.
3
How do I fix CVE-2010-1935?
To fix CVE-2010-1935, disable register_globals and ensure proper input validation in the dsn[phptype] parameter.
4
What software is affected by CVE-2010-1935?
CVE-2010-1935 impacts openMairie Openpresse version 1.01.
5
Can CVE-2010-1935 lead to arbitrary file execution?
Yes, CVE-2010-1935 allows remote attackers to include and execute arbitrary local files.