- Patch available:
- CVSS vector:
- Raven PHP Scripts: Keep It Simple Guest Book
Vulnerability descriptionDirectory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.