Description
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.
Affected products
- campware.org / campsite2.6.0 – 2.6.0
- campware.org / campsite2.6.1 – 2.6.1