Remote File Inclusion Vulnerability in Carbonize Lazarus Guestbook
CVE-2007-1486

Currently unrated

Key Information:

Vendor

Carbonize

Vendor
CVE Published:
16 March 2007

What is CVE-2007-1486?

A remote file inclusion vulnerability exists in the Carbonize Lazarus Guestbook within the template.class.php file. This flaw allows attackers to execute arbitrary PHP code by crafting a malicious URL accessed via the include_path parameter in admin.php. The root cause is likely linked to dynamic variable evaluation, exposing installations prior to version 1.7.3 to significant security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.