CVE-2008-3211 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.26% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-07-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| scripteen | free image hosting script |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber | 2008-07-13 |
References
- http://secunia.com/advisories/31083
- http://securityreason.com/securityalert/4014
- http://www.securityfocus.com/bid/30217
- http://www.vupen.com/english/advisories/2008/2106/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43771
- https://www.exploit-db.com/exploits/6070
- http://secunia.com/advisories/31083
- http://securityreason.com/securityalert/4014
- http://www.securityfocus.com/bid/30217
- http://www.vupen.com/english/advisories/2008/2106/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43771
- https://www.exploit-db.com/exploits/6070
→ the Explorer · watch your stack · NVD