Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-0841

Опубликовано: 31 мар. 2009
Источник: debian
EPSS Низкий

Описание

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mapserverfixed5.2.2-1package

Примечания

  • this doesn't work under linux as the root from the directory traversal needs to exist

EPSS

Процентиль: 73%
0.00786
Низкий

Связанные уязвимости

ubuntu
почти 17 лет назад

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

nvd
почти 17 лет назад

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

github
почти 4 года назад

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

EPSS

Процентиль: 73%
0.00786
Низкий