CVE Database
/

CVE-2010-1944

Back to search

CVE-2010-1944

Published: May 18, 2010

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple PHP remote file inclusion vulnerabilities in openMairie openCimetiere 2.01, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) autorisation.class.php, (2) courrierautorisation.class.php, (3) droit.class.php, (4) profil.class.php, (5) temp_defunt_sansemplacement.class.php, (6) utils.class.php, (7) cimetiere.class.php, (8) defunt.class.php, (9) emplacement.class.php, (10) tab_emplacement.class.php, (11) temp_emplacement.class.php, (12) voie.class.php, (13) collectivite.class.php, (14) defunttransfert.class.php, (15) entreprise.class.php, (16) temp_autorisation.class.php, (17) travaux.class.php, (18) zone.class.php, (19) courrier.class.php, (20) dossier.class.php, (21) plans.class.php, (22) temp_defunt.class.php, and (23) utilisateur.class.php in obj/.

VendorProductVersions

n/a

n/a

affected
n/a

References

64238
vdb-entry
x_refsource_OSVDB
64231
vdb-entry
x_refsource_OSVDB
64223
vdb-entry
x_refsource_OSVDB
64237
vdb-entry
x_refsource_OSVDB
64228
vdb-entry
x_refsource_OSVDB
64230
vdb-entry
x_refsource_OSVDB
64244
vdb-entry
x_refsource_OSVDB
64239
vdb-entry
x_refsource_OSVDB
64225
vdb-entry
x_refsource_OSVDB
12476
exploit
x_refsource_EXPLOIT-DB
64227
vdb-entry
x_refsource_OSVDB
39883
vdb-entry
x_refsource_BID
64245
vdb-entry
x_refsource_OSVDB
64242
vdb-entry
x_refsource_OSVDB
64234
vdb-entry
x_refsource_OSVDB
64232
vdb-entry
x_refsource_OSVDB
39687
third-party-advisory
x_refsource_SECUNIA
64229
vdb-entry
x_refsource_OSVDB
64235
vdb-entry
x_refsource_OSVDB
64233
vdb-entry
x_refsource_OSVDB
64241
vdb-entry
x_refsource_OSVDB
64240
vdb-entry
x_refsource_OSVDB
64236
vdb-entry
x_refsource_OSVDB
ADV-2010-1050
vdb-entry
x_refsource_VUPEN
64226
vdb-entry
x_refsource_OSVDB
64243
vdb-entry
x_refsource_OSVDB
64224
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now