CVE-2013-7262: OSGeo Mapserver
Medium severity, CVSS 6.8. EPSS: 2.2% chance of exploitation in the next 30 days.
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
Affected products
- OSGeo Mapserver: up to and including 6.4.0; version 4.2.0 only; version 4.4.0 only; version 4.6.0 only; version 4.8.0 only; version 4.10.0 only; …
- Umn Mapserver: version 5.2.3 only; version 5.6.7 only; version 6.0.0 only
Published 2014-01-05. Last modified 2026-06-17.