Unrated severityNVD Advisory· Published Dec 31, 2009· Updated Apr 23, 2026
CVE-2009-4529
CVE-2009-4529
Description
InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page via a trailing encoded space character in a URI, as demonstrated by /index.html%20 and /index.php%20 URIs.
Affected products
3cpe:2.3:a:intervations:navicopa_web_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:intervations:navicopa_web_server:*:*:*:*:*:*:*:*range: <=3.0.1.2
- cpe:2.3:a:intervations:navicopa_web_server:2.01:*:*:*:*:*:*:*
- cpe:2.3:a:intervations:navicopa_web_server:3.01:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.packetstormsecurity.org/0910-exploits/navicopa-disclose.txtnvdExploit
- www.securityfocus.com/bid/36705nvdExploit
- secunia.com/advisories/37014nvdVendor Advisory
- www.vupen.com/english/advisories/2009/2927nvdVendor Advisory
- freetexthost.com/n5l0h34pxcnvdURL Repurposed
- osvdb.org/58949nvd
- pocoftheday.blogspot.com/2009/10/navicopa-web-server-3012-remote-source.htmlnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53799nvd
News mentions
0No linked articles in our index yet.