PT-2020-7212 · Gateway Geomatics · Mapserver

Published

2020-01-09

·

Updated

2020-01-22

·

CVE-2012-2950

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Gateway Geomatics MapServer for Windows versions prior to 3.0.6
Description The issue allows remote attackers to execute local PHP code and obtain sensitive information due to a Local File Include Vulnerability.
Recommendations For versions prior to 3.0.6, update to version 3.0.6 or later to resolve the issue.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2950

Affected Products

Mapserver