CVE-2011-3502: Infoleak
Published Sep 16, 2011
·Updated
The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot).
Affected Software
5 affected components
Cogentdatahub Cogent Datahub=7.0
Cogentdatahub Cogent Datahub=7.1.1.63
Cogentdatahub Cogent Datahub=7.1.1
Cogentdatahub Cogent Datahub=7.1.0
Cogentdatahub Cogent Datahub=7.0.2
Event History
Sep 16, 2011
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-3502?
CVE-2011-3502 has a moderate severity rating due to its potential to expose sensitive source code.
2
How do I fix CVE-2011-3502?
To fix CVE-2011-3502, upgrade to a later version of Cogent DataHub that addresses this vulnerability.
3
What impact does CVE-2011-3502 have on affected systems?
CVE-2011-3502 allows remote attackers to access and possibly exploit source code, increasing risk of further attacks.
4
Which versions of Cogent DataHub are affected by CVE-2011-3502?
CVE-2011-3502 affects Cogent DataHub versions 7.0, 7.1.0, 7.1.1, and 7.1.1.63.
5
Can CVE-2011-3502 be exploited remotely?
Yes, CVE-2011-3502 can be exploited remotely by attackers through specially crafted requests.