Jamroom Cookie Authentication Bypass Vulnerability and Multiple Unspecified Security Vulnerabilities

BID:30406

Info

Jamroom Cookie Authentication Bypass Vulnerability and Multiple Unspecified Security Vulnerabilities

Bugtraq ID: 30406
Class: Unknown
CVE: CVE-2008-3376
CVE-2008-3375
Remote: Yes
Local: No
Published: Jul 28 2008 12:00AM
Updated: Jul 05 2016 10:01PM
Credit: James Bercegay of the GulfTech Security Research Team and the vendor are credited with discovering these vulnerabilities.
Vulnerable: Jamroom Jamroom 3.3.8
Jamroom Jamroom 3.3.5
Jamroom Jamroom 3.0.16
Not Vulnerable: Jamroom Jamroom 3.4

Discussion

Jamroom Cookie Authentication Bypass Vulnerability and Multiple Unspecified Security Vulnerabilities

Jamroom is prone to fourteen security vulnerabilities, including an authentication-bypass vulnerability that occurs because the application fails to verify user-supplied data.

Very few technical details are available regarding the remaining security vulnerabilities. We will update this BID when more information is disclosed.

An attacker can exploit the authentication-bypass vulnerability to gain administrative access to the affected application; other attacks are also possible. Effects of the remaining security vulnerabilities are not currently known.

Exploit / POC

Jamroom Cookie Authentication Bypass Vulnerability and Multiple Unspecified Security Vulnerabilities

Attackers can exploit the authentication-bypass vulnerability with a browser.

The following exploit code is available:

Solution / Fix

Jamroom Cookie Authentication Bypass Vulnerability and Multiple Unspecified Security Vulnerabilities

Solution:
The vendor released Jamroom 3.4.0 to address these issues. Please see the references for more information.


Jamroom Jamroom 3.0.16

Jamroom Jamroom 3.3.5

Jamroom Jamroom 3.3.8

References

Jamroom Cookie Authentication Bypass Vulnerability and Multiple Unspecified Security Vulnerabilities

References:
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report