Lucene search

K
nvd[email protected]NVD:CVE-2013-7262
HistoryJan 05, 2014 - 8:55 p.m.

CVE-2013-7262

2014-01-0520:55:04
CWE-89
web.nvd.nist.gov
1

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.002

Percentile

52.5%

SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.

Affected configurations

Nvd
Node
osgeomapserverRange6.4.0
OR
osgeomapserverMatch4.2.0beta1
OR
osgeomapserverMatch4.4.0
OR
osgeomapserverMatch4.4.0beta1
OR
osgeomapserverMatch4.4.0beta2
OR
osgeomapserverMatch4.4.0beta3
OR
osgeomapserverMatch4.6.0
OR
osgeomapserverMatch4.6.0beta1
OR
osgeomapserverMatch4.6.0beta2
OR
osgeomapserverMatch4.6.0beta3
OR
osgeomapserverMatch4.6.0rc1
OR
osgeomapserverMatch4.8.0beta1
OR
osgeomapserverMatch4.8.0beta2
OR
osgeomapserverMatch4.8.0beta3
OR
osgeomapserverMatch4.8.0rc1
OR
osgeomapserverMatch4.8.0rc2
OR
osgeomapserverMatch4.10.0
OR
osgeomapserverMatch4.10.0beta1
OR
osgeomapserverMatch4.10.0beta2
OR
osgeomapserverMatch4.10.0beta3
OR
osgeomapserverMatch4.10.0rc1
OR
osgeomapserverMatch4.10.1
OR
osgeomapserverMatch4.10.2
OR
osgeomapserverMatch4.10.3
OR
osgeomapserverMatch4.10.4
OR
osgeomapserverMatch4.10.5
OR
osgeomapserverMatch5.0.0
OR
osgeomapserverMatch5.0.0beta1
OR
osgeomapserverMatch5.0.0beta2
OR
osgeomapserverMatch5.0.0beta3
OR
osgeomapserverMatch5.0.0beta4
OR
osgeomapserverMatch5.0.0beta5
OR
osgeomapserverMatch5.0.0beta6
OR
osgeomapserverMatch5.0.0rc1
OR
osgeomapserverMatch5.0.0rc2
OR
osgeomapserverMatch5.2.0
OR
osgeomapserverMatch5.2.0beta1
OR
osgeomapserverMatch5.2.0beta2
OR
osgeomapserverMatch5.2.0beta3
OR
osgeomapserverMatch5.2.0beta4
OR
osgeomapserverMatch5.2.0rc1
OR
osgeomapserverMatch5.2.1
OR
osgeomapserverMatch5.4.0
OR
osgeomapserverMatch5.4.0beta1
OR
osgeomapserverMatch5.4.0beta2
OR
osgeomapserverMatch5.4.0beta3
OR
osgeomapserverMatch5.4.0beta4
OR
osgeomapserverMatch5.4.0rc1
OR
osgeomapserverMatch5.4.0rc2
OR
osgeomapserverMatch5.4.1
OR
osgeomapserverMatch5.4.2
OR
osgeomapserverMatch5.6.0
OR
osgeomapserverMatch5.6.1
OR
osgeomapserverMatch5.6.3
OR
osgeomapserverMatch6.0.1
OR
osgeomapserverMatch6.0.2
OR
osgeomapserverMatch6.0.3
OR
osgeomapserverMatch6.2.0
OR
osgeomapserverMatch6.2.1
OR
umnmapserverMatch5.2.3
OR
umnmapserverMatch5.6.7
OR
umnmapserverMatch6.0.0
VendorProductVersionCPE
osgeomapserver*cpe:2.3:a:osgeo:mapserver:*:*:*:*:*:*:*:*
osgeomapserver4.2.0cpe:2.3:a:osgeo:mapserver:4.2.0:beta1:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:*:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta1:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta2:*:*:*:*:*:*
osgeomapserver4.4.0cpe:2.3:a:osgeo:mapserver:4.4.0:beta3:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:*:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta1:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta2:*:*:*:*:*:*
osgeomapserver4.6.0cpe:2.3:a:osgeo:mapserver:4.6.0:beta3:*:*:*:*:*:*
Rows per page:
1-10 of 621

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.002

Percentile

52.5%