CVE-2014-2352: Cogent DataHub Path Traversal
Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname.
Other sources
The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulnerability may enable an attacker to access a limited number of hardcoded file types. Further exploitation of this vulnerability may allow an attacker to cause the web server component to enter a denial-of-service condition.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2352?
CVE-2014-2352 has a medium severity level due to its potential for arbitrary file access and web server denial of service.
How do I fix CVE-2014-2352?
To fix CVE-2014-2352, upgrade to Cogent DataHub version 7.3.5 or later.
What impact can an attacker have by exploiting CVE-2014-2352?
An attacker exploiting CVE-2014-2352 can read sensitive files or cause a denial of service in the web server.
Which versions of Cogent DataHub are affected by CVE-2014-2352?
CVE-2014-2352 affects Cogent DataHub versions prior to 7.3.5, including versions from 7.0 to 7.3.4.
Is CVE-2014-2352 a denial of service vulnerability?
Yes, CVE-2014-2352 can be exploited to cause a denial of service in the affected web server.