CVE Vulnerabilities

CVE-2007-2971

Published: Jun 01, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

Affected Software

NameVendorStart VersionEnd Version
GcardsGreg_neustaetter*1.46 (including)
GcardsGreg_neustaetter1.13 (including)1.13 (including)
GcardsGreg_neustaetter1.43 (including)1.43 (including)
GcardsGreg_neustaetter1.44 (including)1.44 (including)
GcardsGreg_neustaetter1.45 (including)1.45 (including)

References