9.3
CVSSv2

CVE-2008-3167

Published: 14/07/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote malicious users to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin.

Vulnerable Product Search on Vulmon Subscribe to Product

boonex dolphin 6.1.2

Exploits

# Name Of Script : Dolphin PHP # Version : 612 # Download From : heanetdlsourceforgenet/sourceforge/boonex-dolphin/Dolphin-v612-Freezip # Found By : RoMaNcYxHaCkEr [ RoMaNTiC-TeaM ] # My Home Page : WwW4RxHCoM [ We Will Be Back Soon ] & Tryagcc/cc [ Member From Tryag Forum ] # Type Of Exploit : RFI In Multiple Files # I ...