Vulnerability CVE-2011-2703


Published: 2011-08-01   Modified: 2012-02-13

Description:
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
UMN -> Mapserver 

 References:
http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html
http://trac.osgeo.org/mapserver/ticket/3903
http://www.debian.org/security/2011/dsa-2285
http://www.openwall.com/lists/oss-security/2011/07/19/11
http://www.openwall.com/lists/oss-security/2011/07/19/14
http://www.openwall.com/lists/oss-security/2011/07/20/15
http://www.securityfocus.com/bid/48720
https://bugzilla.redhat.com/show_bug.cgi?id=722545
https://bugzilla.redhat.com/show_bug.cgi?id=723293
https://exchange.xforce.ibmcloud.com/vulnerabilities/68682

Copyright 2024, cxsecurity.com

 

Back to Top