CVE-2006-1346
gCards <1.45 - Path Traversal
Title source: llmDescription
Directory traversal vulnerability in inc/setLang.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in a lang[*][file] parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included by index.php.
Exploits (1)
References (6)
Scores
EPSS
0.0859
EPSS Percentile
92.4%
Details
Status
published
Products (3)
greg_neustaetter/gcards
1.43
greg_neustaetter/gcards
1.44
greg_neustaetter/gcards
< 1.45
Published
Mar 22, 2006
Tracked Since
Feb 18, 2026