20020723 Cobalt Qube 3 Administration pagemailing list
http://archives.neohapsis.com/archives/bugtraq/2002-07/0261.html CVE-2002-1058
Cobalt Qube 3.0 - Authentication Bypass
Record summary
CVE-2002-1058 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCobalt Qube 3.0 - Authentication BypassExploitDB exploitby pokleyNot analyzed1 file
References
4cobalt-qube-admin-access(9669)vdb entry
http://www.iss.net/security_center/static/9669.php 5297vdb entry
http://www.securityfocus.com/bid/5297 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1058