PT-2002-2064 · Cobalt · Cobalt Qube

Publicado

2002-08-31

·

Atualizado

2008-09-05

·

CVE-2002-1058

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Cobalt Qube version 3.0
Description: A directory traversal issue exists in the splashAdmin.php file, allowing local users and remote attackers to gain privileges as the Qube Admin. This is achieved by using .. (dot dot) sequences in the sessionId cookie to point to an alternate session file.
Recommendations: For Cobalt Qube version 3.0, consider restricting access to the splashAdmin.php file until a patch is available. As a temporary workaround, avoid using the sessionId cookie with .. (dot dot) sequences to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1058

Produtos afetados

Cobalt Qube