Exploitation Summary
EIP tracks 1 public exploit for CVE-2002-1058. PoCs published by pokley.
AI-analyzed exploit summary This exploit leverages a weak authentication mechanism in Cobalt Qube by manipulating the sessionId cookie to bypass authentication and gain administrative privileges. The PoC demonstrates directory traversal to reference arbitrary files, enabling privilege escalation.
Description
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.
Exploits (1)
This exploit leverages a weak authentication mechanism in Cobalt Qube by manipulating the sessionId cookie to bypass authentication and gain administrative privileges. The PoC demonstrates directory traversal to reference arbitrary files, enabling privilege escalation.