Vulnerabilities > Greg Neustaetter

DATE CVE VULNERABILITY TITLE RISK
2007-06-01 CVE-2007-2971 SQL Injection vulnerability in gCards GetNewsItem.PHP
SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
network
low complexity
greg-neustaetter
7.5
2006-03-22 CVE-2006-1348 Input Validation vulnerability in Gcards 1.43/1.44
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an error message.
4.3
2006-03-22 CVE-2006-1347 Input Validation vulnerability in Gcards 1.43/1.44
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
network
low complexity
greg-neustaetter
7.5
2006-03-22 CVE-2006-1346 Input Validation vulnerability in Gcards 1.43/1.44
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
network
low complexity
greg-neustaetter
6.4
2005-11-01 CVE-2005-3408 SQL Injection vulnerability in Greg Neustaetter Gcards 1.43
SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands via the limit parameter.
network
low complexity
greg-neustaetter
7.5