VULNERABILITY INTELLIGENCE

CVE-2011-2703

CVSS score7.5 HIGH
EPSS probability2.73%
CISA KEVNot currently listed
Published2011-08-01
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:P/I:P/A:P

Description

Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

Weakness classification

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Primary references