CVE-2010-1921 Information

Description

Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00 when register_globals is enabled allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) annuaire.class.php (2) droit.class.php (3) collectivite.class.php (4) profil.class.php (5) direction.class.php (6) service.class.php (7) directiongenerale.class.php and (8) utilisateur.class.php in obj/.

Reference

http://packetstormsecurity.org/1005-exploits/openmairie-rfilfi.txt http://secunia.com/advisories/39673 http://www.exploit-db.com/exploits/12486 http://www.osvdb.org/64176 http://www.osvdb.org/64177 http://www.osvdb.org/64178 http://www.osvdb.org/64179 http://www.osvdb.org/64180 http://www.osvdb.org/64181 http://www.osvdb.org/64182 http://www.osvdb.org/64184 http://www.securityfocus.com/bid/39887 http://www.vupen.com/english/advisories/2010/1059

Share on: