CVE-2008-3375

UnknownEPSS 3.56%

Last modified

CVE-2008-3375 is a vulnerability of currently unknown severity. The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.. EPSS estimates a 3.56% chance of exploitation in the next 30 days.

Description

The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.

Metrics

EPSS Probability
3.56%

87.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
JamroomJamroom<= 3.3.8
JamroomJamroom1.0
JamroomJamroom2.0.9A
JamroomJamroom2.6.10
JamroomJamroom2.6.11
JamroomJamroom2.6.12
JamroomJamroom2.60
JamroomJamroom2.61
JamroomJamroom2.62
JamroomJamroom2.63
JamroomJamroom2.64
JamroomJamroom2.65
JamroomJamroom2.66
JamroomJamroom2.67
JamroomJamroom2.68
JamroomJamroom2.69
JamroomJamroom3.0
JamroomJamroom3.0.1
JamroomJamroom3.0.2
JamroomJamroom3.0.3
JamroomJamroom3.0.4
JamroomJamroom3.0.5
JamroomJamroom3.0.6
JamroomJamroom3.0.7
JamroomJamroom3.0.8
JamroomJamroom3.0.9
JamroomJamroom3.0.10
JamroomJamroom3.0.11
JamroomJamroom3.0.12
JamroomJamroom3.0.13
JamroomJamroom3.0.14
JamroomJamroom3.0.15
JamroomJamroom3.0.16
JamroomJamroom3.0.17
JamroomJamroom3.0.18
JamroomJamroom3.0.19
JamroomJamroom3.0.20
JamroomJamroom3.0.21
JamroomJamroom3.0.22
JamroomJamroom3.0.23
JamroomJamroom3.0.24
JamroomJamroom3.0.25
JamroomJamroom3.0.26
JamroomJamroom3.0.27
JamroomJamroom3.0.28
JamroomJamroom3.0.29
JamroomJamroom3.0.30
JamroomJamroom3.1.0
JamroomJamroom3.1.1
JamroomJamroom3.1.2

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2008-3375?
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.
How severe is CVE-2008-3375?
Severity scoring for CVE-2008-3375 is pending analysis. The EPSS model estimates a 3.56% probability of exploitation in the next 30 days.
How do I fix CVE-2008-3375?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2008-3375?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST