Record summary

CVE-2002-0430 has a selected CVSS score of 3.7; EIP currently links 2 catalogued exploits.

Description

MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBCobalt RaQ 2.0/3.0/4.0 XTR - 'MultiFileUpload.php' Authentication Bypass (1)ExploitDB exploitby Wouter ter MaatNot analyzed1 file
ExploitDB

PoC details
ExploitDBCobalt RaQ 2.0/3.0/4.0 XTR - 'MultiFileUpload.php' Authentication Bypass (2)ExploitDB exploitby Wouter ter MaatNot analyzed1 file
ExploitDB

PoC details

References

3