CVE-2008-3166
BoonEx Ray 3.5 - RCE
Title source: llmDescription
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sIncPath parameter.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by RoMaNcYxHaCkEr · textwebappsphp
https://www.exploit-db.com/exploits/6028
References (5)
Scores
EPSS
0.0338
EPSS Percentile
87.4%
Details
CWE
CWE-94
Status
published
Products (1)
boonex/ray
3.5
Published
Jul 14, 2008
Tracked Since
Feb 18, 2026