| Vulnerability Name: | CVE-2007-4542 (CCN-36236) | ||||||||||||||||||||||||
| Assigned: | 2007-08-22 | ||||||||||||||||||||||||
| Published: | 2007-08-22 | ||||||||||||||||||||||||
| Updated: | 2011-03-08 | ||||||||||||||||||||||||
| Summary: | Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in mapserv.c in the mapserv CGI program. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
| References: | Source: CCN Type: Debian Bug report logs - #439346 XSS issue Source: MISC Type: UNKNOWN http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439346 Source: MITRE Type: CNA CVE-2007-4542 Source: CONFIRM Type: UNKNOWN http://mapserver.gis.umn.edu/download/current/HISTORY.TXT/ Source: CCN Type: SA26561 MapServer Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 26561 Source: SECUNIA Type: UNKNOWN 26718 Source: SECUNIA Type: UNKNOWN 29688 Source: MISC Type: UNKNOWN http://trac.osgeo.org/mapserver/attachment/ticket/2256/ms-bug-2256-4.8.patch Source: CCN Type: Mapserver Web site: Ticket #2256 XSS vulnerabilities in mapserv CGI Source: CONFIRM Type: UNKNOWN http://trac.osgeo.org/mapserver/ticket/2256 Source: DEBIAN Type: UNKNOWN DSA-1539 Source: DEBIAN Type: DSA-1539 mapserver -- several vulnerabilities Source: CCN Type: OSVDB ID: 39378 MapServer maptemplate.c processLine Function XSS Source: CCN Type: OSVDB ID: 39379 MapServer mapserv.c writeError Function XSS Source: BID Type: UNKNOWN 25582 Source: CCN Type: BID-25582 MapServer Multiple Remote Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2007-2974 Source: XF Type: UNKNOWN mapserver-multiple-xss(36236) Source: FEDORA Type: UNKNOWN FEDORA-2007-2018 | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||