CVE-2010-1948
openMairie Openfoncier 2.00 - Remote File Inclusion via soustab.php dsn[phptype] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1948. PoCs published by cr4wl3r.
AI-analyzed exploit summary The exploit demonstrates RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Openfoncier 2.00. It provides specific URLs with injectable parameters to include remote or local files, enabling arbitrary code execution or sensitive file disclosure.
Description
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.
Exploits (1)
The exploit demonstrates RFI (Remote File Inclusion) and LFI (Local File Inclusion) vulnerabilities in Openfoncier 2.00. It provides specific URLs with injectable parameters to include remote or local files, enabling arbitrary code execution or sensitive file disclosure.