CVE-2008-3167
BoonEx Dolphin 6.1.2 - Remote Code Execution via dir[plugins] or sIncPath Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3167. PoCs published by RoMaNcYxHaCkEr.
AI-analyzed exploit summary The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Dolphin PHP 6.1.2, where multiple files improperly include remote URLs via user-controlled parameters. The PoC provides specific URLs with malicious payloads hosted on an external server.
Description
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin.
Exploits (1)
The exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Dolphin PHP 6.1.2, where multiple files improperly include remote URLs via user-controlled parameters. The PoC provides specific URLs with malicious payloads hosted on an external server.