{"api_version":"1","generated_at":"2026-07-23T13:35:15+00:00","cve":"CVE-2008-3268","urls":{"html":"https://cve.report/CVE-2008-3268","api":"https://cve.report/api/cve/CVE-2008-3268.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-3268","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-3268"},"summary":{"title":"CVE-2008-3268","description":"Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-07-24 15:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-264","NVD-CWE-noinfo","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/30300","name":"http://www.securityfocus.com/bid/30300","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"phpScheduleIt 'useLogonName' Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43900","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43900","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31147","name":"http://secunia.com/advisories/31147","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"phpScheduleIt \"useLogonName\" Security Bypass - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://sourceforge.net/project/shownotes.php?release_id=614202","name":"http://sourceforge.net/project/shownotes.php?release_id=614202","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SourceForge.net: phpScheduleIt: Files","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-3268","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-3268","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.0","cpe7":"beta","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.0","cpe7":"rc1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"3268","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"brickhost","cpe5":"phpscheduleit","cpe6":"1.2.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T09:28:42.031Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://sourceforge.net/project/shownotes.php?release_id=614202"},{"name":"30300","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30300"},{"name":"phpscheduleit-unspecified-security-bypass(43900)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43900"},{"name":"31147","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31147"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://sourceforge.net/project/shownotes.php?release_id=614202"},{"name":"30300","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30300"},{"name":"phpscheduleit-unspecified-security-bypass(43900)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43900"},{"name":"31147","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31147"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-3268","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://sourceforge.net/project/shownotes.php?release_id=614202","refsource":"CONFIRM","url":"http://sourceforge.net/project/shownotes.php?release_id=614202"},{"name":"30300","refsource":"BID","url":"http://www.securityfocus.com/bid/30300"},{"name":"phpscheduleit-unspecified-security-bypass(43900)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/43900"},{"name":"31147","refsource":"SECUNIA","url":"http://secunia.com/advisories/31147"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-3268","datePublished":"2008-07-24T15:18:00.000Z","dateReserved":"2008-07-24T00:00:00.000Z","dateUpdated":"2024-08-07T09:28:42.031Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-07-24 15:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-264","NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"7663D802-7547-4FE0-B5A3-D20B18ADB6E9"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.0:beta:*:*:*:*:*:*","matchCriteriaId":"D69ADD45-37E8-480F-8C06-3295A9BB5B78"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.0:rc1:*:*:*:*:*:*","matchCriteriaId":"FC0D9466-E7BD-4D1C-9AFA-596198A5B65E"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.1:*:*:*:*:*:*:*","matchCriteriaId":"CFB149A8-0B97-438B-8351-91446232D500"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.2:*:*:*:*:*:*:*","matchCriteriaId":"1FCC62CE-E455-449C-A03E-23C97D834143"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.3:*:*:*:*:*:*:*","matchCriteriaId":"3019FB4F-E2E1-4E4B-B537-F6E12262950B"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.4:*:*:*:*:*:*:*","matchCriteriaId":"5D209B2F-11D9-4C66-AA9D-ABF706B436A6"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.5:*:*:*:*:*:*:*","matchCriteriaId":"82A187A7-6985-464C-B9E5-81FFB815261D"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.6:*:*:*:*:*:*:*","matchCriteriaId":"F79B653B-9D13-4B72-83EB-E3DB806B815B"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.7:*:*:*:*:*:*:*","matchCriteriaId":"8B218350-9512-4C0A-9BDD-3DF7CE26921E"},{"vulnerable":true,"criteria":"cpe:2.3:a:brickhost:phpscheduleit:1.2.9:*:*:*:*:*:*:*","matchCriteriaId":"0CDB5CB2-19E6-4CF9-90A5-44FC4E1CC683"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"3268","Ordinal":"1","Title":"CVE-2008-3268","CVE":"CVE-2008-3268","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"3268","Ordinal":"1","NoteData":"Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2008-3268"},{"CveYear":"2008","CveId":"3268","Ordinal":"2","NoteData":"2008-07-24","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"3268","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}