CVE

Id
4822  
CVE No.
CVE-2002-0430  
Status
Candidate  
Description
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.  
Phase
Proposed (20020611)  
Votes
MODIFY(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REVIEWING(1) Alderson  
Comments
Frech> XF:cobalt-multifileupload-bypass-auth(8395)