The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulnerability may enable an attacker to access a limited number of hardcoded file types. Further exploitation of this vulnerability may allow an attacker to cause the web server component to enter a denial-of-service condition.
History

Fri, 03 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
Description Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname. The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulnerability may enable an attacker to access a limited number of hardcoded file types. Further exploitation of this vulnerability may allow an attacker to cause the web server component to enter a denial-of-service condition.
Title Cogent DataHub Path Traversal
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:P'}

cvssV2_0

{'score': 7.8, 'vector': 'AV:N/AC:L/Au:N/C:C/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2014-05-30T23:00:00

Updated: 2025-10-03T16:31:41.797Z

Reserved: 2014-03-13T00:00:00

Link: CVE-2014-2352

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-05-30T23:55:02.847

Modified: 2025-10-03T17:15:45.107

Link: CVE-2014-2352

cve-icon Redhat

No data.