[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2014-3225":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":40,"aliases":69,"duplicate_of":9,"upstream":71,"downstream":72,"duplicates":79,"related":80,"reserved_at":9,"published_at":82,"modified_at":83,"state":84,"summary":85,"references_raw":93,"kevs":158,"epss":159,"epss_history":162,"metrics":409,"affected":414},"CVE-2014-3225","Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],[41,50,55],{"_key":42,"name":43,"source":44,"url":45,"maturity":46,"reliability_score":47,"verified":48,"type":9,"platforms":49,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_84613993CED57B25","Exploit Reference (youtube.com)","reference","https://www.youtube.com/watch?v=vuBaoQUFEYQ&feature=youtu.be","unknown",0.2,false,[],{"_key":51,"name":52,"source":44,"url":53,"maturity":46,"reliability_score":47,"verified":48,"type":9,"platforms":54,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_D44CAB9531F0484F","Exploit Reference (packetstormsecurity.com)","http://packetstormsecurity.com/files/126553/Cobbler-Local-File-Inclusion.html",[],{"_key":56,"name":57,"source":58,"url":59,"maturity":60,"reliability_score":61,"verified":48,"type":9,"platforms":62,"requires_auth":9,"exploitdb":64,"metasploit":9},"33252","Cobbler 2.4.x \u003C 2.6.x - Local File Inclusion","exploit-database","https://www.exploit-db.com/exploits/33252","poc",0.5,[63],"php",{"verified":48,"type":65,"platform":63,"file":66,"codes":67},"webapps","exploits/php/webapps/33252.txt",[7,68],"OSVDB-106759",[70],"GHSA-xc7w-jvhx-p6q9",[],[73,75,77],{"_key":74},"UBUNTU-CVE-2014-3225",{"_key":76},"OPENSUSE-SU-2024:10282-1",{"_key":78},"USN-6475-1",[],[81],{"_key":76},"2014-05-14T00:00:00.000Z","2024-08-06T10:35:57.073Z","Modified",{"cisa_kev":48,"cisa_ransomware":48,"cisa_vendor":9,"epss_severity":86,"epss_score":87,"severity":88,"severity_score":89,"severity_version":90,"severity_source":91,"severity_vector":92,"severity_status":84},"low",0.06113,"medium",4,"v2.0","nvd","AV:N/AC:L/Au:S/C:P/I:N/A:N",[94,103,108,114,119,123,127,130,135,140,145,149,153],{"url":95,"sources":96,"tags":99},"http://seclists.org/oss-sec/2014/q2/274",[97,91,98],"cve.org","osv_pypi",[100,101,102],"Mailing List","X Refsource MLIST","WEB",{"url":104,"sources":105,"tags":106},"https://github.com/cobbler/cobbler/issues/939",[97,91,98],[107,102],"X Refsource MISC",{"url":109,"sources":110,"tags":111},"http://www.osvdb.org/106759",[97,91,98],[112,113,102],"VDB Entry","X Refsource OSVDB",{"url":115,"sources":116,"tags":117},"http://www.securityfocus.com/bid/67277",[97,91,98],[112,118,102],"X Refsource BID",{"url":120,"sources":121,"tags":122},"http://seclists.org/oss-sec/2014/q2/273",[97,91,98],[100,101,102],{"url":45,"sources":124,"tags":125},[97,91,98],[107,126,102],"Exploit",{"url":53,"sources":128,"tags":129},[97,91,98],[107,126,102],{"url":131,"sources":132,"tags":133},"http://www.securityfocus.com/archive/1/532094/100/0/threaded",[97,91,98],[100,134,102],"X Refsource BUGTRAQ",{"url":136,"sources":137,"tags":138},"http://www.exploit-db.com/exploits/33252",[97,91,98],[126,139,102],"X Refsource EXPLOIT DB",{"url":141,"sources":142,"tags":143},"https://nvd.nist.gov/vuln/detail/CVE-2014-3225",[98],[144],"Advisory",{"url":146,"sources":147,"tags":148},"https://github.com/cobbler/cobbler/commit/8232c0e88ec7382d3f8d3bf48c81a4a91ac4325d",[98],[102],{"url":150,"sources":151,"tags":152},"https://github.com/cobbler/cobbler/commit/f757e3096fcd32397609ca38efb01f19d16dd634",[98],[102],{"url":154,"sources":155,"tags":156},"https://github.com/cobbler/cobbler",[98],[157],"PACKAGE",[],{"date":160,"score":87,"percentile":161},"2026-06-04",0.90942,[163,167,169,172,175,178,180,182,185,188,191,194,196,199,202,205,208,211,214,216,219,222,225,228,230,233,236,239,242,245,248,251,254,257,259,261,264,267,270,273,276,279,281,284,286,289,291,293,296,299,302,305,307,309,312,315,318,321,324,326,328,331,334,337,339,342,345,348,351,353,355,358,361,364,367,370,373,375,377,379,382,385,388,391,394,397,400,402,404,406],{"date":164,"score":165,"percentile":166},"2025-11-04",0.06296,0.9052,{"date":168,"score":165,"percentile":166},"2025-11-05",{"date":170,"score":165,"percentile":171},"2025-11-06",0.90519,{"date":173,"score":165,"percentile":174},"2025-11-07",0.90527,{"date":176,"score":165,"percentile":177},"2025-11-08",0.90529,{"date":179,"score":165,"percentile":174},"2025-11-09",{"date":181,"score":165,"percentile":174},"2025-11-10",{"date":183,"score":165,"percentile":184},"2025-11-11",0.90526,{"date":186,"score":165,"percentile":187},"2025-11-12",0.90533,{"date":189,"score":165,"percentile":190},"2025-11-13",0.90537,{"date":192,"score":165,"percentile":193},"2025-11-14",0.9054,{"date":195,"score":165,"percentile":190},"2025-11-15",{"date":197,"score":165,"percentile":198},"2025-11-16",0.90541,{"date":200,"score":165,"percentile":201},"2025-11-17",0.90538,{"date":203,"score":165,"percentile":204},"2025-11-18",0.90018,{"date":206,"score":165,"percentile":207},"2025-11-19",0.90022,{"date":209,"score":165,"percentile":210},"2025-11-20",0.90025,{"date":212,"score":165,"percentile":213},"2025-11-21",0.90543,{"date":215,"score":165,"percentile":213},"2025-11-22",{"date":217,"score":165,"percentile":218},"2025-11-23",0.90544,{"date":220,"score":165,"percentile":221},"2025-11-24",0.90545,{"date":223,"score":165,"percentile":224},"2025-11-25",0.90547,{"date":226,"score":165,"percentile":227},"2025-11-26",0.90546,{"date":229,"score":165,"percentile":221},"2025-11-27",{"date":231,"score":165,"percentile":232},"2025-11-28",0.90535,{"date":234,"score":165,"percentile":235},"2025-11-29",0.9057,{"date":237,"score":165,"percentile":238},"2025-11-30",0.90569,{"date":240,"score":165,"percentile":241},"2025-12-01",0.90627,{"date":243,"score":165,"percentile":244},"2025-12-02",0.90626,{"date":246,"score":165,"percentile":247},"2025-12-03",0.90628,{"date":249,"score":165,"percentile":250},"2025-12-04",0.90568,{"date":252,"score":165,"percentile":253},"2025-12-05",0.90574,{"date":255,"score":165,"percentile":256},"2025-12-06",0.90575,{"date":258,"score":165,"percentile":238},"2025-12-07",{"date":260,"score":165,"percentile":238},"2025-12-08",{"date":262,"score":165,"percentile":263},"2025-12-09",0.90572,{"date":265,"score":165,"percentile":266},"2025-12-10",0.90581,{"date":268,"score":165,"percentile":269},"2025-12-11",0.90588,{"date":271,"score":165,"percentile":272},"2025-12-12",0.90593,{"date":274,"score":165,"percentile":275},"2025-12-13",0.90586,{"date":277,"score":165,"percentile":278},"2025-12-14",0.90584,{"date":280,"score":165,"percentile":278},"2025-12-15",{"date":282,"score":165,"percentile":283},"2025-12-16",0.90585,{"date":285,"score":165,"percentile":272},"2025-12-17",{"date":287,"score":165,"percentile":288},"2025-12-18",0.90599,{"date":290,"score":165,"percentile":288},"2025-12-19",{"date":292,"score":165,"percentile":288},"2025-12-20",{"date":294,"score":165,"percentile":295},"2025-12-21",0.9061,{"date":297,"score":165,"percentile":298},"2025-12-22",0.90606,{"date":300,"score":165,"percentile":301},"2025-12-23",0.90615,{"date":303,"score":165,"percentile":304},"2025-12-24",0.90625,{"date":306,"score":165,"percentile":247},"2025-12-25",{"date":308,"score":165,"percentile":244},"2025-12-26",{"date":310,"score":165,"percentile":311},"2025-12-27",0.90676,{"date":313,"score":87,"percentile":314},"2025-12-28",0.90471,{"date":316,"score":87,"percentile":317},"2025-12-29",0.90468,{"date":319,"score":87,"percentile":320},"2025-12-30",0.90474,{"date":322,"score":87,"percentile":323},"2025-12-31",0.90485,{"date":325,"score":87,"percentile":224},"2026-01-01",{"date":327,"score":87,"percentile":193},"2026-01-02",{"date":329,"score":87,"percentile":330},"2026-01-03",0.90539,{"date":332,"score":87,"percentile":333},"2026-01-04",0.90484,{"date":335,"score":87,"percentile":336},"2026-01-05",0.90481,{"date":338,"score":87,"percentile":333},"2026-01-06",{"date":340,"score":87,"percentile":341},"2026-01-07",0.90486,{"date":343,"score":87,"percentile":344},"2026-01-08",0.90489,{"date":346,"score":87,"percentile":347},"2026-01-09",0.9049,{"date":349,"score":87,"percentile":350},"2026-01-10",0.90491,{"date":352,"score":87,"percentile":333},"2026-01-11",{"date":354,"score":87,"percentile":333},"2026-01-12",{"date":356,"score":87,"percentile":357},"2026-01-13",0.90482,{"date":359,"score":87,"percentile":360},"2026-01-14",0.90497,{"date":362,"score":87,"percentile":363},"2026-01-15",0.905,{"date":365,"score":87,"percentile":366},"2026-01-16",0.90503,{"date":368,"score":87,"percentile":369},"2026-01-17",0.90501,{"date":371,"score":87,"percentile":372},"2026-01-18",0.90502,{"date":374,"score":87,"percentile":372},"2026-01-19",{"date":376,"score":87,"percentile":372},"2026-01-20",{"date":378,"score":87,"percentile":366},"2026-01-21",{"date":380,"score":87,"percentile":381},"2026-01-22",0.90506,{"date":383,"score":87,"percentile":384},"2026-01-23",0.90515,{"date":386,"score":87,"percentile":387},"2026-01-24",0.90522,{"date":389,"score":87,"percentile":390},"2026-01-25",0.90523,{"date":392,"score":87,"percentile":393},"2026-01-26",0.90525,{"date":395,"score":87,"percentile":396},"2026-01-27",0.90528,{"date":398,"score":87,"percentile":399},"2026-01-28",0.90534,{"date":401,"score":87,"percentile":232},"2026-01-29",{"date":403,"score":87,"percentile":187},"2026-01-30",{"date":405,"score":87,"percentile":218},"2026-01-31",{"date":407,"score":87,"percentile":408},"2026-02-01",0.90601,[410],{"source":91,"cvss_v2_0":411,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":89,"baseSeverity":9,"vectorString":92,"impactScore":412,"exploitabilityScore":413},2.9,8,[415,435],{"ecosystem":9,"name":416,"vendor":417,"product":416,"cpe_part":418,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":419},"cobbler","cobblerd","a",[420,423,425,427,429,431,433],{"version":421,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.4.0","cpe",{"version":424,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.4.0:1",{"version":426,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.4.1",{"version":428,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.4.2",{"version":430,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.4.3",{"version":432,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.4.4",{"version":434,"is_range":48,"range_type":422,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.6.0",{"ecosystem":436,"name":416,"vendor":436,"product":416,"cpe_part":9,"purl_type":437,"purl_namespace":9,"purl_name":416,"source":9,"versions":438},"PyPI","pypi",[439,446],{"version":440,"is_range":441,"range_type":442,"version_start":434,"version_start_type":443,"version_end":444,"version_end_type":445,"fixed_in":9},"gte2_6_0_lt2_6_4",true,"ecosystem","including","2.6.4","excluding",{"version":447,"is_range":441,"range_type":442,"version_start":421,"version_start_type":443,"version_end":448,"version_end_type":445,"fixed_in":9},"gte2_4_0_lt2_4_7","2.4.7"]