CVE-2006-1347

gCards < 1.45 - SQL Injection via Username Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1347. PoCs published by rgod.

AI-analyzed exploit summary This exploit demonstrates two vulnerabilities in gCards <= 1.45: arbitrary local file inclusion via the 'setLang' parameter and SQL injection for admin authentication bypass. It allows remote command execution by injecting PHP code into log files or bypassing authentication to upload malicious files.

Description

SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1595

This exploit demonstrates two vulnerabilities in gCards <= 1.45: arbitrary local file inclusion via the 'setLang' parameter and SQL injection for admin authentication bypass. It allows remote command execution by injecting PHP code into log files or bypassing authentication to upload malicious files.

Classification
Working Poc 100%
Attack Type
Rce | Sqli | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: gCards <= 1.45
No auth needed
Prerequisites: Target must have gCards <= 1.45 installed · For action 1: Log files must be writable and accessible via path traversal · For action 2: magic_quotes_gpc must be Off
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1595
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24017
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19322
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1015
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17165
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25344
Various Sources mailing-list x_refsource_vim
http://attrition.org/pipermail/vim/2006-April/000698.html

Scores

EPSS 0.0263
EPSS Percentile 83.5%

Details

Status published
Products (3)
greg_neustaetter/gcards 1.43
greg_neustaetter/gcards 1.44
greg_neustaetter/gcards < 1.45
Published Mar 22, 2006
Tracked Since Feb 18, 2026