CVE-2008-3268
Last modified
CVE-2008-3268 is a vulnerability of currently unknown severity. Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these details are obtained from third party information.. EPSS estimates a 1.86% chance of exploitation in the next 30 days.
Description
Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Brickhost | Phpscheduleit | 1.2.0 |
| Brickhost | Phpscheduleit | 1.2.1 |
| Brickhost | Phpscheduleit | 1.2.2 |
| Brickhost | Phpscheduleit | 1.2.3 |
| Brickhost | Phpscheduleit | 1.2.4 |
| Brickhost | Phpscheduleit | 1.2.5 |
| Brickhost | Phpscheduleit | 1.2.6 |
| Brickhost | Phpscheduleit | 1.2.7 |
| Brickhost | Phpscheduleit | 1.2.9 |
References
- http://secunia.com/advisories/31147Vendor Advisory
- http://secunia.com/advisories/31147Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3268?
How severe is CVE-2008-3268?
How do I fix CVE-2008-3268?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3262Cross-site request forgery (CSRF) vulnerability in Claroline…
- CVE-2008-3263The IAX2 protocol implementation in Asterisk Open Source 1.0…
- CVE-2008-3264The FWDOWNL firmware-download implementation in Asterisk Ope…
- CVE-2008-3265SQL injection vulnerability in the DT Register (com_dtregist…
- CVE-2008-3266SQL injection vulnerability in picture_pic_bv.asp in SoftAci…
- CVE-2008-3267SQL injection vulnerability in mojoJobs.cgi in MojoJobs allo…
- CVE-2008-3269WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 …
- CVE-2008-3270yum-rhn-plugin in Red Hat Enterprise Linux (RHEL) 5 does not…
- CVE-2008-3271Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote a…
- CVE-2008-3272The snd_seq_oss_synth_make_info function in sound/core/seq/o…
- CVE-2008-3273JBoss Enterprise Application Platform (aka JBossEAP or EAP) …
- CVE-2008-3274The default configuration of Red Hat Enterprise IPA 1.0.0 an…
Are you affected by CVE-2008-3268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
