6.4
CVSSv2

CVE-2006-1346

Published: 22/03/2006 Updated: 11/10/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and previous versions allows remote malicious users to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

greg neustaetter gcards

greg neustaetter gcards 1.43

greg neustaetter gcards 1.44

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "gCards <= 145 multiple vulnerabilities\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n\r\n"; echo "Sun-Tzu:\"At first, then, exhibit the coyness of a maiden, until the\r\n"; echo "enemy gives you an opening; afterwards emulate the rapidity of a\r\n"; ...