Security Advisory

CVE-2009-0841

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-03-31 18:00:00
Last updated 2024-08-07 04:48:52
Assigner mitre
State PUBLISHED

Description

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.