CVE-2010-1928
openMairie openPlanning 1.00 - Remote File Inclusion via soustab.php dsn[phptype] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1928. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Openplanning 1.00. It provides URLs to exploit the vulnerabilities by injecting malicious paths into the 'path_om' and 'dsn[phptype]' parameters.
Description
Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Exploits (1)
This exploit demonstrates RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Openplanning 1.00. It provides URLs to exploit the vulnerabilities by injecting malicious paths into the 'path_om' and 'dsn[phptype]' parameters.