← Vulnerability feed

Vulnerability record · CVE-2008-3167 · published 14 July 2008

CVE-2008-3167: Boonex dolphin code injection vulnerability

Boonex · Dolphin

Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin.

9.3 CVSS 2.0 High EPSS 6.5% · top 6.5% CWE-94 · Code injection
9.3CVSS 2.0 base score
6.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3167 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2013-3638Boonex dolphin sql injection vulnerabilitySQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' param…EPSS 1.4%6.8CVE-2014-4333Boonex dolphin cross-site request forgery vulnerabilityCross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the aut…EPSS 0.94%6.5CVE-2014-3810Boonex dolphin sql injection vulnerabilitySQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute …EPSS 1.7%5.1CVE-2006-5410Boonex dolphin vulnerabilityPHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PH…EPSS 1.5%5.1CVE-2006-4189Boonex dolphin vulnerabilityMultiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] para…EPSS 6.3%5.0CVE-2011-3728Boonex dolphin information exposure vulnerabilityDolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …EPSS 1.2%4.8CVE-2021-27969Boonex dolphin cross-site scripting vulnerabilityDolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.EPSS 0.67%4.3CVE-2012-0873Boonex dolphin cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via …EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2008-3167), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.