peter bassill · operator
$ cve CVE-2008-3292 JSON

CVE-2008-3292 EXPLOIT

6.4
MEDIUM · CVSS 2.0 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin cookie, as demonstrated via addpage.php.

Scoring

CVSS6.4 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
EPSS7.32% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2008-07-24
Last modified2026-06-16

Affected (1)

VendorProduct
ezwebalbumezwebalbum

Public exploits

SourceTitleDate
exploit-dbEZWebAlbum - Insecure Cookie Handling2008-07-21

References

→ the Explorer  ·  watch your stack  ·  NVD