CVE-2014-3225
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.
- Cobblerd Cobbler
- = 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.4.4, 2.6.0
- Fix
- Available
- CVSS 2.0
- 4.0 MEDIUM
- EPSS
- 8.9% (95th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2014-05-14
CVE-2014-3225 at NVD
2 known exploits for CVE-2014-3225
Proof-of-concept code and exploit modules indexed by Sploitus