Svi
Pretraži prema proizvođaču
Pretraži prema CWE oznaci
O usluzi
Pretplate
Jezik
hr
en
CVE-2011-2703 - CERT CVE
CVE-2011-2703
ID
CVE-2011-2703
Sažetak
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
Reference
http://secunia.com/advisories/45368
https://bugzilla.redhat.com/show_bug.cgi?id=722545
http://www.securityfocus.com/bid/48720
http://www.openwall.com/lists/oss-security/2011/07/19/11
http://www.openwall.com/lists/oss-security/2011/07/19/14
https://bugzilla.redhat.com/show_bug.cgi?id=723293
http://www.debian.org/security/2011/dsa-2285
http://trac.osgeo.org/mapserver/ticket/3903
http://secunia.com/advisories/45257
http://lists.osgeo.org/pipermail/mapserver-users/2011-July/069430.html
http://secunia.com/advisories/45318
http://www.openwall.com/lists/oss-security/2011/07/20/15
https://exchange.xforce.ibmcloud.com/vulnerabilities/68682
CVSS
Base:
7.5
Impact:
6.4
Exploitability:
10.0
Pristup
Vektor
Složenost
Autentikacija
NETWORK
LOW
NONE
Impact
Povjerljivost
Cjelovitost
Dostupnost
PARTIAL
PARTIAL
PARTIAL
CVSS vektor
AV:N/AC:L/Au:N/C:P/I:P/A:P
Zadnje važnije ažuriranje
07-06-2021 - 15:55
Objavljeno
01-08-2011 - 19:55