Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2009-0841
HistoryMar 31, 2009 - 6:24 p.m.

CVE-2009-0841

2009-03-3118:24:45
Debian Security Bug Tracker
security-tracker.debian.org
11

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.025

Percentile

90.2%

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a โ€ฆ (dot dot) in the id parameter.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.025

Percentile

90.2%