Remote File Inclusion Vulnerability in Carbonize Lazarus Guestbook
CVE-2007-1486
Currently unrated
What is CVE-2007-1486?
A remote file inclusion vulnerability exists in the Carbonize Lazarus Guestbook within the template.class.php file. This flaw allows attackers to execute arbitrary PHP code by crafting a malicious URL accessed via the include_path parameter in admin.php. The root cause is likely linked to dynamic variable evaluation, exposing installations prior to version 1.7.3 to significant security risks.
