peter bassill · operator
$ cve CVE-2002-1058 JSON

CVE-2002-1058 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 4.4% (pctl 91)

Patch early

A public exploit exists.

Description

Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS4.37% — more likely to be exploited than 91% of all CVEs
On CISA KEVno
Public exploityes
Published2002-10-04
Last modified2026-06-16

Affected (1)

VendorProduct
cobaltqube

Public exploits

SourceTitleDate
exploit-dbCobalt Qube 3.0 - Authentication Bypass2002-07-24

References

→ the Explorer  ·  watch your stack  ·  NVD