greg_neustaetter CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

greg_neustaetter vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to greg_neustaetter, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2007-2971 SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter. [email protected] 7.5 2.00% 2007-06-01 2026-04-23
CVE-2006-5255 PHP remote file inclusion vulnerability in addnews.php in Greg Neustaetter gCards 1.13 allows remote attackers to execute arbitrary PHP code via a URL in the languagefile parameter. NOTE: another researcher has observed that languageFile is defined before use. CVE analysis as of 20061012 concurs with the dispute [email protected] 7.5 1.68% 2006-10-12 2026-04-23
CVE-2006-1348 Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to inject arbitrary web script or HTML via the lang[*][file] parameter, which is injected into an error message. NOTE: this issue might be resultant from CVE-2006-1346. [email protected] 4.3 8.85% 2006-03-22 2026-04-16
CVE-2006-1347 SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. [email protected] 7.5 1.36% 2006-03-22 2026-04-16
CVE-2006-1346 Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php. [email protected] 6.4 8.60% 2006-03-22 2026-04-16
CVE-2005-3408 SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands via the limit parameter. [email protected] 7.5 0.89% 2005-11-01 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence