Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.
https://github.com/cobbler/cobbler/issues/939
http://www.securityfocus.com/bid/67277
http://www.securityfocus.com/archive/1/532094/100/0/threaded