A vulnerability has been identified in Rama Zaiten CMS, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by an input validation error in the "download.php" script that does not validate the "file" parameter before being passed as an argument to a "readfile()" call, which could be exploited to disclose the contents of arbitrary files.
Vulnerable Products
Vulnerable Software: Rama Zaiten CMS version 0.9.7.8 and prior