CVE-2010-1936: Path Traversal
Published May 12, 2010
·Updated
Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Affected Software
1 affected component
openMairie openComInterne=1.01
Event History
May 12, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1936?
The severity of CVE-2010-1936 is medium with a score of 6.8.
2
How do I fix CVE-2010-1936?
To fix CVE-2010-1936, disable register_globals and ensure proper validation of user inputs.
3
What kind of attacks can be executed using CVE-2010-1936?
CVE-2010-1936 allows attackers to perform directory traversal attacks to include and execute arbitrary local files.
4
Which software is affected by CVE-2010-1936?
CVE-2010-1936 affects the openMairie openComInterne version 1.01.
5
What is a related vulnerability to CVE-2010-1936?
CVE-2007-2069 is a related issue to CVE-2010-1936.