"value":"Multiple PHP remote file inclusion vulnerabilities in Advanced Guestbook 2.4.2 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) index.php, (2) addentry.php, or (3) picture.php, a different set of vectors than CVE-2006-5804. NOTE: this issue has been disputed by third party researchers, stating that the include_path variable is instantiated before use"
"value":"** IMPUGNADO ** M\u00faltiples vulnerabilidades PHP de inclusi\u00f3n remota de archivo en Advanced Guestbook 2.4.2 permite a atacantes remotos ejecutar c\u00f3digo PHP de su elecci\u00f3n a trav\u00e9s de una URL en el par\u00e1metro include_path en (1) index.php, (2)addentry.php, o (3) picture.php, un grupo diferente de vectores que CVE-2006-5804. NOTA: este asunto ha sido impugnado por un tercer investigador, se\u00f1alando que la variable include_path est\u00e1 instanciada antes de usarse."