CVE-2009-0841
Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.
Date published : 2009-03-31
http://www.securityfocus.com/bid/34306
http://www.securityfocus.com/archive/1/502271/100/0/threaded