9.3
CVSSv2

CVE-2008-3166

Published: 14/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote malicious users to execute arbitrary PHP code via a URL in the sIncPath parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

boonex ray 3.5

Exploits

# Name Of Script : Dolphin PHP # Version : 612 # Download From : heanetdlsourceforgenet/sourceforge/boonex-dolphin/Dolphin-v612-Freezip # Found By : RoMaNcYxHaCkEr [ RoMaNTiC-TeaM ] # My Home Page : WwW4RxHCoM [ We Will Be Back Soon ] & Tryagcc/cc [ Member From Tryag Forum ] # Type Of Exploit : RFI In Multiple Files # I ...
# Name Of Script : Ray # Version : 35 # Download From : getboonexcom/Ray-v35-Suite-Free # Found By : RoMaNcYxHaCkEr [ RoMaNTiC-TeaM ] # My Home Page : WwW4RxHCoM [ We Will Be Back Soon ] & Tryagcc/cc [ Member From Tryag Forum ] # Type Of Exploit : RFI # POC : WwW4RxHCoM/ray35/modules/global/inc/contentincphp? ...