CVE-2002-1058

Cobalt Qube 3.0 - Directory Traversal via SessionId Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1058. PoCs published by pokley.

AI-analyzed exploit summary This exploit leverages a weak authentication mechanism in Cobalt Qube by manipulating the sessionId cookie to bypass authentication and gain administrative privileges. The PoC demonstrates directory traversal to reference arbitrary files, enabling privilege escalation.

Description

Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by pokley · textwebappsphp
https://www.exploit-db.com/exploits/21640

This exploit leverages a weak authentication mechanism in Cobalt Qube by manipulating the sessionId cookie to bypass authentication and gain administrative privileges. The PoC demonstrates directory traversal to reference arbitrary files, enabling privilege escalation.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Cobalt Qube
No auth needed
Prerequisites: Network access to the target Cobalt Qube appliance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-07/0261.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5297
Patch, Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9669.php

Scores

EPSS 0.0437
EPSS Percentile 90.0%

Details

Status published
Products (1)
cobalt/qube 3.0
Published Oct 04, 2002
Tracked Since Feb 18, 2026