CVE-2008-3127
HIOX Banner Rotator 1.3 - Remote File Inclusion via hm Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3127. PoCs published by Ghost Hacker.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in HBR 1.3 due to improper input validation in the 'hm' parameter of hioxBannerRotate.php. An attacker can include arbitrary remote files by manipulating the parameter.
Description
PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in HBR 1.3 due to improper input validation in the 'hm' parameter of hioxBannerRotate.php. An attacker can include arbitrary remote files by manipulating the parameter.