CVE-2010-1944

Openmairie Opencimetiere - Code Injection

Title source: rule
STIX 2.1

Description

Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2) courrierautorisation.class.php, (3) droit.class.php, (4) profil.class.php, (5) temp_defunt_sansemplacement.class.php, (6) utils.class.php, (7) cimetiere.class.php, (8) defunt.class.php, (9) emplacement.class.php, (10) tab_emplacement.class.php, (11) temp_emplacement.class.php, (12) voie.class.php, (13) collectivite.class.php, (14) defunttransfert.class.php, (15) entreprise.class.php, (16) temp_autorisation.class.php, (17) travaux.class.php, (18) zone.class.php, (19) courrier.class.php, (20) dossier.class.php, (21) plans.class.php, (22) temp_defunt.class.php, and (23) utilisateur.class.php in obj/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by cr4wl3r · textwebappsphp
https://www.exploit-db.com/exploits/12476

References (29)

Core 29
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64241
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64242
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64231
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64232
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64233
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64234
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64235
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64236
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64238
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64237
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64244
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64239
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64240
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64243
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64245
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64223
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64228
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64230
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58267
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64225
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/12476
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64227
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39883
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39687
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64229
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1050
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64226
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/64224

Scores

EPSS 0.0691
EPSS Percentile 91.4%

Details

CWE
CWE-94
Status published
Products (1)
openmairie/opencimetiere 2.01
Published May 19, 2010
Tracked Since Feb 18, 2026