Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter to (1) bugreporter/thankyou.php and (2) feedback/thankyou.php in implementation/management/priv/.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Campsite | Campware.org | 2.6.0 (including) | 2.6.0 (including) |
| Campsite | Campware.org | 2.6.1 (including) | 2.6.1 (including) |