CVE-2008-3401
HIOX Random Ad 1.3 - Remote Code Execution via hm Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3401. PoCs published by Ghost Hacker.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in HIOX Random Ad 1.3 due to improper input validation in the 'hm' parameter. An attacker can inject malicious code via the URL to achieve remote code execution.
Description
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in HIOX Random Ad 1.3 due to improper input validation in the 'hm' parameter. An attacker can inject malicious code via the URL to achieve remote code execution.