CVE-2010-1935
openMairie Openpresse 1.01 - Path Traversal via dsn[phptype] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1935. PoCs published by cr4wl3r.
AI-analyzed exploit summary This exploit demonstrates a Local File Include (LFI) vulnerability in Openpresse 1.01. The PoC shows how an attacker can manipulate the 'dsn[phptype]' parameter in the 'soustab.php' script to include arbitrary local files by appending a null byte (%00).
Description
Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Exploits (1)
This exploit demonstrates a Local File Include (LFI) vulnerability in Openpresse 1.01. The PoC shows how an attacker can manipulate the 'dsn[phptype]' parameter in the 'soustab.php' script to include arbitrary local files by appending a null byte (%00).