First published: Fri Sep 16 2011(Updated: )
The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cogent Datahub | =7.0 | |
Cogent Datahub | =7.1.1.63 | |
Cogent Datahub | =7.1.1 | |
Cogent Datahub | =7.1.0 | |
Cogent Datahub | =7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3502 has a moderate severity rating due to its potential to expose sensitive source code.
To fix CVE-2011-3502, upgrade to a later version of Cogent DataHub that addresses this vulnerability.
CVE-2011-3502 allows remote attackers to access and possibly exploit source code, increasing risk of further attacks.
CVE-2011-3502 affects Cogent DataHub versions 7.0, 7.1.0, 7.1.1, and 7.1.1.63.
Yes, CVE-2011-3502 can be exploited remotely by attackers through specially crafted requests.