4.3
CVSSv2

CVE-2006-1348

Published: 22/03/2006 Updated: 11/10/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an error message. NOTE: this issue might be resultant from CVE-2006-1346.

Vulnerable Product Search on Vulmon Subscribe to Product

greg neustaetter gcards

greg neustaetter gcards 1.43

greg neustaetter gcards 1.44

Exploits

#!/usr/bin/php -q -d short_open_tag=on <? echo "gCards <= 145 multiple vulnerabilities\r\n"; echo "by rgod rgod@autisticiorg\r\n"; echo "site: retrogodaltervistaorg\r\n\r\n"; echo "Sun-Tzu:\"At first, then, exhibit the coyness of a maiden, until the\r\n"; echo "enemy gives you an opening; afterwards emulate the rapidity of a\r\n"; ...