Unrated severityNVD Advisory· Published Dec 31, 2009· Updated Jun 16, 2026
CVE-2009-4529
CVE-2009-4529
Description
InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page via a trailing encoded space character in a URI, as demonstrated by /index.html%20 and /index.php%20 URIs.
Affected products
4cpe:2.3:a:intervations:navicopa_web_server:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:intervations:navicopa_web_server:*:*:*:*:*:*:*:*range: <=3.0.1.2
- cpe:2.3:a:intervations:navicopa_web_server:2.01:*:*:*:*:*:*:*
- cpe:2.3:a:intervations:navicopa_web_server:3.01:*:*:*:*:*:*:*
- (no CPE)range: <=3.0.1.2
Patches
Vulnerability mechanics
References
8- www.packetstormsecurity.org/0910-exploits/navicopa-disclose.txtnvdExploit
- www.securityfocus.com/bid/36705nvdExploit
- secunia.com/advisories/37014nvdVendor Advisory
- www.vupen.com/english/advisories/2009/2927nvdVendor Advisory
- freetexthost.com/n5l0h34pxcnvdURL Repurposed
- osvdb.org/58949nvd
- pocoftheday.blogspot.com/2009/10/navicopa-web-server-3012-remote-source.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53799nvd
News mentions
0No linked articles in our index yet.