CVE-2008-3399
XRMS CRM 1.99.2 - Remote Code Execution via Include Directory Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3399. PoCs published by AzzCoder.
AI-analyzed exploit summary This is a technical writeup detailing multiple vulnerabilities in XMRS CRM, including Remote File Inclusion (RFI), Cross-Site Scripting (XSS), and information disclosure via phpinfo(). The RFI vulnerability requires register_globals to be enabled and targets the $include_directory variable in activities/workflow-activities.php.
Description
PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter.
Exploits (1)
This is a technical writeup detailing multiple vulnerabilities in XMRS CRM, including Remote File Inclusion (RFI), Cross-Site Scripting (XSS), and information disclosure via phpinfo(). The RFI vulnerability requires register_globals to be enabled and targets the $include_directory variable in activities/workflow-activities.php.