Description
Directory traversal vulnerability in the web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in an HTTP request.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://aluigi.altervista.org/adv/cogent_2-adv.txt
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-03.pdf
Scores
EPSS
0.0265
EPSS Percentile
83.8%
Details
CWE
CWE-22
Status
published
Products (5)
cogentdatahub/cogent_datahub
7.0
cogentdatahub/cogent_datahub
7.0.2
cogentdatahub/cogent_datahub
7.1.0
cogentdatahub/cogent_datahub
7.1.1
cogentdatahub/cogent_datahub
7.1.1.63
Published
Sep 16, 2011
Tracked Since
Feb 18, 2026