PT-2009-3439 · Mapserver · Mapserver
Joe Testa
·
Publicado
2009-03-31
·
Atualizado
2021-06-07
·
CVE-2009-0843
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MapServer versions 4.x through 4.10.3
MapServer versions 5.x through 5.2.1
Description
The issue allows remote attackers to determine the existence of arbitrary files via a full pathname in the
queryfile parameter. This is achieved by triggering different error messages depending on whether the specified pathname exists.Recommendations
For MapServer versions 4.x through 4.10.3, update to version 4.10.4 or later.
For MapServer versions 5.x through 5.2.1, update to version 5.2.2 or later.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mapserver