← Back

Greg Neustaetter

greg_neustaetter

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Gcards
gcards

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Greg Neustaetter
1Gcards
Apr 23, 2026
Jun 1, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
1Greg Neustaetter
1Gcards
Apr 23, 2026
Oct 12, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attackers to execute arbitrary PHP code via a URL in the languagefile parameter. NOTE: another researcher has observed...Show more
PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attackers to execute arbitrary PHP code via a URL in the languagefile parameter. NOTE: another researcher has observed that languageFile is defined before use. CVE analysis as of 20061012 concurs with the disputeShow less
1Greg Neustaetter
1Gcards
Apr 16, 2026
Mar 22, 2006
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an...Show more
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an error message. NOTE: this issue might be resultant from CVE-2006-1346.Show less
1Greg Neustaetter
1Gcards
Apr 16, 2026
Mar 22, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
1Greg Neustaetter
1Gcards
Apr 16, 2026
Mar 22, 2006
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] p...Show more
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.Show less
1Greg Neustaetter
1Gcards
Apr 16, 2026
Nov 1, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands via the limit parameter.