PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP through CGI, allows remote attackers to execute arbitrary PHP code via a URL in the default_path_to_themes parameter.Referenceshttp://www.securityfocus.com/bid/21721https://www.exploit-db.com/exploits/2979http://secunia.com/advisories/23477http://www.vupen.com/english/advisories/2006/5147