7.8
CVSSv2

CVE-2009-0843

Published: 31/03/2009 Updated: 07/06/2021
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The msLoadQuery function in mapserv in MapServer 4.x prior to 4.10.4 and 5.x prior to 5.2.2 allows remote malicious users to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

osgeo mapserver 4.10.0

osgeo mapserver 4.8.0

osgeo mapserver 4.6.0

umn mapserver 4.0

osgeo mapserver 4.10.2

osgeo mapserver 4.10.3

osgeo mapserver 4.4.0

osgeo mapserver 5.2.1

osgeo mapserver 5.2.0

osgeo mapserver 5.0.0

osgeo mapserver 4.10.1

osgeo mapserver 4.2.0

Vendor Advisories

Debian Bug report logs - #523027 mapserver: multiple vulnerabilities Package: mapserver; Maintainer for mapserver is Debian GIS Project <pkg-grass-devel@listsaliothdebianorg>; Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 7 Apr 2009 22:51:06 UTC Severity: grave Tags: security Fixed i ...
Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0843 Missing input validation on a user supplied map queryfile name can be used by an attacker to check f ...