4.3
CVSSv2

CVE-2007-4542

Published: 27/08/2007 Updated: 08/03/2011
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in MapServer prior to 4.10.3 allow remote malicious users to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in mapserv.c in the mapserv CGI program.

Vulnerable Product Search on Vulmon Subscribe to Product

university of minnesota mapserver

Vendor Advisories

Chris Schmidt and Daniel Morissette discovered two vulnerabilities in mapserver, a development environment for spatial and mapping applications The Common Vulnerabilities and Exposures project identifies the following two problems: CVE-2007-4542 Lack of input sanitizing and output escaping in the CGI mapserver's template handling and erro ...