Description
The web server in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to obtain the source code of executable files via a request with a trailing (1) space or (2) %2e (encoded dot).
Exploits (1)
References (2)
Core 2
Core References
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-03.pdf
Exploit x_refsource_misc
http://aluigi.altervista.org/adv/cogent_4-adv.txt
Scores
EPSS
0.0453
EPSS Percentile
89.2%
Details
CWE
CWE-200
Status
published
Products (5)
cogentdatahub/cogent_datahub
7.0
cogentdatahub/cogent_datahub
7.0.2
cogentdatahub/cogent_datahub
7.1.0
cogentdatahub/cogent_datahub
7.1.1
cogentdatahub/cogent_datahub
7.1.1.63
Published
Sep 16, 2011
Tracked Since
Feb 18, 2026