CVE-2010-1926 Information

Description

Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta when register_globals is enabled allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter a related issue to CVE-2007-2069. NOTE: some of these details are obtained from third party information.

Reference

http://packetstormsecurity.org/1004-exploits/opencourrier-rfilfi.txt http://secunia.com/advisories/39624 http://www.exploit-db.com/exploits/12398 http://www.osvdb.org/64201 http://www.vupen.com/english/advisories/2010/1003

Share on: