Loading
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
Use CWE-89, Osgeo vendor hub and Mapserver product page to widen CVE-2013-7262 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2010-2540, CVE-2017-5522 and CVE-2025-59431 for nearby disclosures in the same product family.