CVE-2010-1920
OpenMairie openAnnuaire 2.00 - Remote File Inclusion via dsn[phptype] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1920. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Openannuaire Openmairie Annuaire 2.00. It provides multiple endpoints where an attacker can include remote or local files by manipulating the 'path_om' or 'dsn[phptype]' parameters.
Description
Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Exploits (1)
This exploit demonstrates RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Openannuaire Openmairie Annuaire 2.00. It provides multiple endpoints where an attacker can include remote or local files by manipulating the 'path_om' or 'dsn[phptype]' parameters.