CVE-2010-1926
openMairie openCourrier 2.02 and 2.03 beta - Remote File Inclusion via dsn[phptype] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1926. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates multiple RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Opencourrier 2.03beta. The PoC provides URLs that can be manipulated to include arbitrary files, potentially leading to remote code execution or sensitive information disclosure.
Description
Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates multiple RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Opencourrier 2.03beta. The PoC provides URLs that can be manipulated to include arbitrary files, potentially leading to remote code execution or sensitive information disclosure.