CVE-2008-3375

JamRoom <3.4.0 - Auth Bypass

Title source: llm

Description

The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.

Exploits (1)

exploitdb WORKING POC VERIFIED
by GulfTech Security · phpwebappsphp
https://www.exploit-db.com/exploits/32121

Scores

EPSS 0.1250
EPSS Percentile 93.8%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

jamroom/jamroom < 3.3.8
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
jamroom/jamroom
... and 35 more

Timeline

Published Jul 30, 2008
Tracked Since Feb 18, 2026