Vulnerability Details CVE-2010-2540
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.057
EPSS Ranking 90.0%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2010-2540
-
cpe:2.3:a:osgeo:mapserver:4.10.0
-
cpe:2.3:a:osgeo:mapserver:4.10.1
-
cpe:2.3:a:osgeo:mapserver:4.10.2
-
cpe:2.3:a:osgeo:mapserver:4.10.3
-
cpe:2.3:a:osgeo:mapserver:4.10.4
-
cpe:2.3:a:osgeo:mapserver:4.10.5
-
cpe:2.3:a:osgeo:mapserver:4.2.0
-
cpe:2.3:a:osgeo:mapserver:4.2.1
-
cpe:2.3:a:osgeo:mapserver:4.2.2
-
cpe:2.3:a:osgeo:mapserver:4.2.3
-
cpe:2.3:a:osgeo:mapserver:4.2.4
-
cpe:2.3:a:osgeo:mapserver:4.2.5
-
cpe:2.3:a:osgeo:mapserver:4.4.0
-
cpe:2.3:a:osgeo:mapserver:4.4.1
-
cpe:2.3:a:osgeo:mapserver:4.4.2
-
cpe:2.3:a:osgeo:mapserver:4.6.0
-
cpe:2.3:a:osgeo:mapserver:4.6.1
-
cpe:2.3:a:osgeo:mapserver:4.6.2
-
cpe:2.3:a:osgeo:mapserver:4.8.0
-
cpe:2.3:a:osgeo:mapserver:4.8.1
-
cpe:2.3:a:osgeo:mapserver:4.8.2
-
cpe:2.3:a:osgeo:mapserver:4.8.3
-
cpe:2.3:a:osgeo:mapserver:4.8.4
-
cpe:2.3:a:osgeo:mapserver:5.0.0
-
cpe:2.3:a:osgeo:mapserver:5.2
-
cpe:2.3:a:osgeo:mapserver:5.2.0
-
cpe:2.3:a:osgeo:mapserver:5.2.1
-
cpe:2.3:a:osgeo:mapserver:5.4
-
cpe:2.3:a:osgeo:mapserver:5.4.0
-
cpe:2.3:a:osgeo:mapserver:5.4.1
-
cpe:2.3:a:osgeo:mapserver:5.4.2
-
cpe:2.3:a:osgeo:mapserver:5.6.0
-
cpe:2.3:a:osgeo:mapserver:5.6.1
-
cpe:2.3:a:osgeo:mapserver:5.6.2
-
cpe:2.3:a:osgeo:mapserver:5.6.3
-
cpe:2.3:a:umn:mapserver:4.0