CVE-2010-1944 describes multiple remote file inclusion (RFI) vulnerabilities in openMairie openCimetiere version 2.01. These flaws allow unauthenticated remote attackers to execute arbitrary PHP code on affected systems by injecting a malicious URL into the 'path_om' parameter across numerous PHP scripts, provided the deprecated 'register_globals' setting is enabled. The vulnerability has a CVSS v2 score of 6.8 (Medium), indicating a network-based attack with medium complexity, leading to partial confidentiality, integrity, and availability impacts. Its FAUCET Risk Score is high at 90/100, despite a low EPSS score. While not listed on the CISA KEV catalog or Hot List, exploit code is publicly available on ExploitDB (EDB-12476). There is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.01CPE matchmatch criteria | cpe:2.3:a:openmairie:opencimetiere:2.01:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.