
Find real vulnerabilities before they ship
Cobalt RaQ2 and RaQ3 does not properly set the access permissions and ownership for files that are uploaded via FrontPage, which allows attackers to bypass cgiwrap and modify files.
| Base Score | 7.5 |
|---|---|
| Vector String | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |