Back

CVE-2002-1058

Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

Published: Oct 4, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
cobalt qube 3.0

GitHub Security Advisory GHSA-5v9x-cwp3-pcqj

Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 4.37%

Top 10% most likely to be exploited

Threat Score 41.3 / 100

Data Sources

NVD EPSS GitHub