Vulnerability Database

318,389

Total vulnerabilities in the database

CVE-2009-0843

The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.

  • Published: Mar 31, 2009
  • Updated: Nov 9, 2025
  • CVE: CVE-2009-0843
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 7.8
  • AV:N/AC:L/Au:N/C:C/I:N/A:N

CWEs:

Software From Fixed in
umn / mapserver 4.0 4.0.x
umn / mapserver 4.0-beta1 4.0-beta1.x
umn / mapserver 4.0-beta2 4.0-beta2.x
osgeo / mapserver 4.2.0-beta1 4.2.0-beta1.x
osgeo / mapserver 4.4.0-beta1 4.4.0-beta1.x
osgeo / mapserver 4.4.0-beta2 4.4.0-beta2.x
osgeo / mapserver 4.6.0-beta1 4.6.0-beta1.x
osgeo / mapserver 4.6.0-beta2 4.6.0-beta2.x
osgeo / mapserver 4.6.0-beta3 4.6.0-beta3.x
osgeo / mapserver 4.8.0-beta2 4.8.0-beta2.x
osgeo / mapserver 4.8.0-beta1 4.8.0-beta1.x
osgeo / mapserver 4.8.0-beta3 4.8.0-beta3.x
osgeo / mapserver 4.8.0-rc2 4.8.0-rc2.x
osgeo / mapserver 4.8.0-rc1 4.8.0-rc1.x
osgeo / mapserver 4.10.0 4.10.0.x
osgeo / mapserver 4.10.0-beta1 4.10.0-beta1.x
osgeo / mapserver 4.10.0-rc1 4.10.0-rc1.x
osgeo / mapserver 4.10.0-beta3 4.10.0-beta3.x
osgeo / mapserver 4.10.0-beta2 4.10.0-beta2.x
osgeo / mapserver 4.10.2 4.10.2.x
osgeo / mapserver 4.10.1 4.10.1.x
osgeo / mapserver 4.10.3 4.10.3.x
osgeo / mapserver 5.0.0-beta5 5.0.0-beta5.x
osgeo / mapserver 5.0.0-beta6 5.0.0-beta6.x
osgeo / mapserver 5.0.0-beta3 5.0.0-beta3.x
osgeo / mapserver 5.0.0-beta4 5.0.0-beta4.x
osgeo / mapserver 5.0.0-beta1 5.0.0-beta1.x
osgeo / mapserver 5.0.0-beta2 5.0.0-beta2.x
osgeo / mapserver 5.0.0-rc1 5.0.0-rc1.x
osgeo / mapserver 5.2.0 5.2.0.x
osgeo / mapserver 5.2.0-beta2 5.2.0-beta2.x
osgeo / mapserver 5.2.0-beta1 5.2.0-beta1.x
osgeo / mapserver 5.2.0-beta3 5.2.0-beta3.x
osgeo / mapserver 5.2.0-beta4 5.2.0-beta4.x
osgeo / mapserver 5.2.0-rc1 5.2.0-rc1.x
osgeo / mapserver 5.2.1 5.2.1.x
osgeo / mapserver 4.6.0 4.6.0.x
osgeo / mapserver 4.6.0-rc1 4.6.0-rc1.x
osgeo / mapserver 5.0.0-rc2 5.0.0-rc2.x
osgeo / mapserver 5.0.0 5.0.0.x
osgeo / mapserver 4.4.0 4.4.0.x
osgeo / mapserver 4.4.0-beta3 4.4.0-beta3.x