Back to search
CVE-2011-2703
Published: Aug 1, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
45318
third-party-advisory
x_refsource_SECUNIA
http://trac.osgeo.org/mapserver/ticket/3903
x_refsource_CONFIRM
[oss-security] 20110719 CVE Request -- MapServer -- SQL injections in OGC filter encoding and in WMS time support.
mailing-list
x_refsource_MLIST
45257
third-party-advisory
x_refsource_SECUNIA
DSA-2285
vendor-advisory
x_refsource_DEBIAN
https://bugzilla.redhat.com/show_bug.cgi?id=723293
x_refsource_CONFIRM
45368
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.redhat.com/show_bug.cgi?id=722545
x_refsource_CONFIRM
[mapserver-users] 20110713 MapServer 6.0.1, 5.6.7 and 4.10.7 releases with security fixes
mailing-list
x_refsource_MLIST
mapserver-multiple-sql-injection(68682)
vdb-entry
x_refsource_XF
48720
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now