CVE-2011-3500: Path Traversal
Directory traversal vulnerability in the web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2011-3500?
CVE-2011-3500 is a directory traversal vulnerability in Cogent DataHub that allows remote attackers to read arbitrary files via a specially crafted HTTP request.
What versions of Cogent DataHub are affected by CVE-2011-3500?
Cogent DataHub versions 7.1.1.63 and earlier, including 7.0, 7.0.2, and 7.1.0 are affected by CVE-2011-3500.
What are the potential impacts of CVE-2011-3500?
CVEs related to directory traversal can lead to unauthorized access to sensitive files on the server, potentially exposing critical data.
How do I fix CVE-2011-3500?
To mitigate the impact of CVE-2011-3500, upgrade to a patched version of Cogent DataHub beyond 7.1.1.63.
Is there a workaround for CVE-2011-3500 if I cannot upgrade?
A potential workaround for CVE-2011-3500 may include restricting access to sensitive files via network controls or configuring the web server to block directory traversal patterns.