CVE-2016-20079 | jamie Dharma Booking up to 2.28.3 proccess.php gateway filename control (Exploit 39592 / EDB-39592)

SecurityVulns

A vulnerability labeled as problematic has been found in jamie Dharma Booking up to 2.28.3. Affected by this vulnerability is an unknown functionality of the file proccess.php. Such manipulation of the argument gateway leads to improper control of filename for include/require statement in php program (‘php remote file inclusion’). This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is listed as CVE-2016-20079. The attack may be performed from remote. In addition, an exploit is available.VulDB Recent EntriesRead More