CVE-2010-1999: Path Traversal
Published May 20, 2010
·Updated
Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when registerglobals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Affected Software
1 affected component
openMairie Opencatalogue=1.024
Event History
May 20, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-1999?
CVE-2010-1999 has a medium severity score of 6.8.
2
How do I fix CVE-2010-1999?
To fix CVE-2010-1999, disable register_globals in the PHP configuration and update OpenMairie Opencatalogue to the latest version.
3
What kind of vulnerability is CVE-2010-1999?
CVE-2010-1999 is a directory traversal vulnerability.
4
Who is affected by CVE-2010-1999?
CVE-2010-1999 affects users of OpenMairie Opencatalogue version 1.024 when register_globals is enabled.
5
What can attackers do with CVE-2010-1999?
Attackers can exploit CVE-2010-1999 to include and execute arbitrary local files on the server.