First published: Tue Jun 11 2002(Updated: )
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun Cobalt RaQ | ||
Sun Cobalt RaQ | ||
Sun Cobalt RaQ |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0430 is classified as a high severity vulnerability as it allows local users to bypass authentication and overwrite arbitrary files.
To mitigate CVE-2002-0430, ensure that access controls are implemented to prevent local users from exploiting symlink attacks.
CVE-2002-0430 affects Sun Cobalt RaQ versions 2, 3i, and 4.
The impact of CVE-2002-0430 is that it allows unauthorized file access and potential execution of malicious code due to file overwriting.
No, CVE-2002-0430 requires local access to the system to execute the symlink attack.