2021-08-27 19:10:31
mitre
PUBLISHED
The GET parameter "id" in WMS v1.0 is passed without filtering, which allows attackers to perform SQL injection.