CVE-2014-3225

Cobbler 2.4.x-2.6.x - Authenticated Path Traversal via Kickstart Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3225. PoCs published by Dolev Farhi.

AI-analyzed exploit summary This is a writeup describing a Local File Inclusion (LFI) vulnerability in Cobbler versions 2.4.x to 2.6.x. The exploit involves creating a new profile in the Cobbler WebUI and setting the Kickstart value to a local file path (e.g., /etc/passwd), which is then displayed when viewing the Kickstart file.

Description

Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

Exploits (1)

exploitdb WRITEUP
by Dolev Farhi · textwebappsphp
https://www.exploit-db.com/exploits/33252

This is a writeup describing a Local File Inclusion (LFI) vulnerability in Cobbler versions 2.4.x to 2.6.x. The exploit involves creating a new profile in the Cobbler WebUI and setting the Kickstart value to a local file path (e.g., /etc/passwd), which is then displayed when viewing the Kickstart file.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Cobbler 2.4.x - 2.6.x
Auth required
Prerequisites: Access to Cobbler WebUI · Valid credentials to create a profile
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q2/274
Issue Tracking x_refsource_misc
https://github.com/cobbler/cobbler/issues/939
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/106759
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67277
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2014/q2/273
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/532094/100/0/threaded
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/33252

Scores

EPSS 0.0611
EPSS Percentile 91.0%

Details

CWE
CWE-22
Status published
Products (7)
cobblerd/cobbler 2.4.0 (2 CPE variants)
cobblerd/cobbler 2.4.1
cobblerd/cobbler 2.4.2
cobblerd/cobbler 2.4.3
cobblerd/cobbler 2.4.4
cobblerd/cobbler 2.6.0
pypi/cobbler 2.6.0 - 2.6.4PyPI
Published May 14, 2014
Tracked Since Feb 18, 2026