Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.80065
Category:Web application abuses
Title:gCards < 1.46 Multiple Vulnerabilities - Active Check
Summary:gCards is prone to multiple vulnerabilities.
Description:Summary:
gCards is prone to multiple vulnerabilities.

Vulnerability Insight:
gCards fails to sanitize user input to the 'setLang' parameter
in the 'inc/setLang.php' script which is called by 'index.php'.

Vulnerability Impact:
An unauthenticated attacker may be able to exploit this issue to
read arbitrary local files or execute code from local files subject to the permissions of the web
server user id.

There are also reportedly other flaws in the installed application, including a directory
traversal issue that allows reading of local files as well as a SQL injection (SQLi) and a
cross-site scripting (XSS) issue.

Solution:
Update to version 1.46 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2006-1346
BugTraq ID: 17165
http://www.securityfocus.com/bid/17165
https://www.exploit-db.com/exploits/1595
http://www.osvdb.org/24016
http://secunia.com/advisories/19322
http://attrition.org/pipermail/vim/2006-April/000698.html
http://www.vupen.com/english/advisories/2006/1015
Common Vulnerability Exposure (CVE) ID: CVE-2006-1347
http://www.osvdb.org/24017
XForce ISS Database: gcards-loginfunction-sql-injection(25344)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25344
Common Vulnerability Exposure (CVE) ID: CVE-2006-1348
http://www.osvdb.org/24018
XForce ISS Database: gcards-incsetlang-xss(25343)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25343
CopyrightCopyright (C) 2008 Josh Zlatin-Amishav

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.