CVE-2011-2703

MapServer < 4.10.7, 5.x < 5.6.7, 6.x < 6.0.1 - SQL Injection via OGC Filter Encoding or WMS Time Support

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

References (13)

Core 13
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45318
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/19/11
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45257
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2011/dsa-2285
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/19/14
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45368
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/68682
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/48720
Patch mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/07/20/15

Scores

EPSS 0.0273
EPSS Percentile 84.6%

Details

CWE
CWE-89
Status published
Products (16)
osgeo/mapserver 4.2.0 beta1
osgeo/mapserver 4.4.0 (4 CPE variants)
osgeo/mapserver 4.6.0 (5 CPE variants)
osgeo/mapserver 4.8.0 beta1 (5 CPE variants)
osgeo/mapserver 4.10.0 (5 CPE variants)
osgeo/mapserver 4.10.1
osgeo/mapserver 4.10.2
osgeo/mapserver 4.10.3
osgeo/mapserver 4.10.4
osgeo/mapserver 4.10.5
... and 6 more
Published Aug 01, 2011
Tracked Since Feb 18, 2026