CVE-2010-1947: Path Traversal
Published May 18, 2010
·Updated
Directory traversal vulnerability in scr/soustab.php in openMairie Openregistrecil 1.02, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter. NOTE: this may be related to CVE-2007-2069.
Affected Software
1 affected component
openMairie Openregistrecil=1.02
Event History
May 18, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 19, 2010
Data Sourced
via NVD·12:07 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1947?
CVE-2010-1947 has a medium severity rating of 6.8.
2
How do I fix CVE-2010-1947?
To fix CVE-2010-1947, disable register_globals in your PHP configuration and apply any available patches for openMairie Openregistrecil.
3
What type of vulnerability is CVE-2010-1947?
CVE-2010-1947 is classified as a directory traversal vulnerability.
4
What impact can CVE-2010-1947 have?
CVE-2010-1947 can allow remote attackers to include and execute arbitrary local files on the server.
5
In which software is CVE-2010-1947 found?
CVE-2010-1947 is found in openMairie Openregistrecil version 1.02.