← Vulnerability feed

Vulnerability record · CVE-2008-3268 · published 24 July 2008

CVE-2008-3268: Brickhost phpscheduleit permissions and access controls vulnerability

Brickhost · Phpscheduleit

Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these details are obtained from third party information.

6.8 CVSS 2.0 Medium EPSS 1.9% · top 21.6% CWE-264 · Permissions and access controls
6.8CVSS 2.0 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email address knowledge to bypass restrictions and gain privileges via unspecified vectors related to login names. NOTE: some of these details are obtained from third party information.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3268 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2004-1652Brickhost phpscheduleit vulnerabilityphpScheduleIt 1.0.0 RC1 does not clear administrative privileges if the administrator logs in as a normal user, which allows users with physical acce…EPSS 1.1%6.8CVE-2008-6132Brickhost phpscheduleit code injection vulnerabilityEval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execut…EPSS 26%5.0CVE-2004-2469Brickhost phpscheduleit vulnerabilityUnspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.EPSS 1.2%4.3CVE-2004-1651Brickhost phpscheduleit vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the registration page in phpScheduleIt 1.0.0 RC1 allow remote attackers to inject arbitrary we…EPSS 1.3%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed7.8CVE-2016-3643SolarWinds Virtualization Manager sudo misconfiguration privilege escalationSolarWinds Virtualization Manager 6.3.1 and earlier ship with a misconfigured sudo policy that lets a local user run privileged commands, as shown by…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2008-3268), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.