CVE-2008-5308
UnknownEPSS 7.28%
Last modified
CVE-2008-5308 is a vulnerability of currently unknown severity. The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.. EPSS estimates a 7.28% chance of exploitation in the next 30 days.
Description
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lovecms | The Simple Forum | 3.1d |
References
- http://secunia.com/advisories/32758Vendor Advisory
- http://secunia.com/advisories/32758Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5308?
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.
How severe is CVE-2008-5308?
Severity scoring for CVE-2008-5308 is pending analysis. The EPSS model estimates a 7.28% probability of exploitation in the next 30 days.
How do I fix CVE-2008-5308?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5302Race condition in the rmtree function in File::Path 1.08 and…
- CVE-2008-5303Race condition in the rmtree function in File::Path 1.08 (li…
- CVE-2008-5304Cross-site scripting (XSS) vulnerability in TWiki before 4.2…
- CVE-2008-5305Eval injection vulnerability in TWiki before 4.2.4 allows re…
- CVE-2008-5306SQL injection vulnerability in admin/index.php in PG Real Es…
- CVE-2008-5307SQL injection vulnerability in admin/index.php in PG Roommat…
- CVE-2008-5309SQL injection vulnerability in NetArt Media Real Estate Port…
- CVE-2008-5310SQL injection vulnerability in image.php in NetArt Media Car…
- CVE-2008-5311SQL injection vulnerability in image.php in NetArt Media Blo…
- CVE-2008-5312mailscanner 4.55.10 and other versions before 4.74.16-1 migh…
- CVE-2008-5313mailscanner 4.68.8 and other versions before 4.74.16-1 might…
- CVE-2008-5314Stack consumption vulnerability in libclamav/special.c in Cl…
Are you affected by CVE-2008-5308?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
