peter bassill · operator
$ cve CVE-2008-3508 JSON

CVE-2008-3508 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 3% (pctl 87)

Patch early

A public exploit exists.

Description

LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS2.98% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2008-08-07
Last modified2026-06-16

Affected (1)

VendorProduct
wogan maylitenews

Public exploits

SourceTitleDate
exploit-dbLiteNews 0.1 - Insecure Cookie Handling2008-08-05

References

→ the Explorer  ·  watch your stack  ·  NVD