Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1710. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in SIESTTA 2.0 via the 'idioma' parameter in login.php and a Cross-Site Scripting (XSS) vulnerability in carga_foto_al.php via the 'usuario' parameter. Both vulnerabilities require register_globals to be enabled.
Description
Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in SIESTTA 2.0 via the 'idioma' parameter in login.php and a Cross-Site Scripting (XSS) vulnerability in carga_foto_al.php via the 'usuario' parameter. Both vulnerabilities require register_globals to be enabled.