CVE-2008-3375
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 3.6%
from disclosure to weapon0 days
Published on NVDJul 30
1st PoCJul 28
exploitation probability
3.6%top 12% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/32121⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/31249http://securityreason.com/securityalert/4069https://exchange.xforce.ibmcloud.com/vulnerabilities/44048http://www.gulftech.org/?node=research&article_id=00117-07282008http://www.jamroom.net/index.php?m=td_tracker&o=view&id=1178http://www.jamroom.net/phpBB2/viewtopic.php?t=24454http://www.securityfocus.com/archive/1/494820/100/0/threadedhttp://www.securityfocus.com/bid/30406