PT-2006-5990 · Gcards · Gcards

Str0Ke

·

Published

2006-10-12

·

Updated

2024-08-07

·

CVE-2006-5255

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions gCards version 1.13
Description A remote file inclusion issue exists, allowing remote attackers to execute arbitrary PHP code. This is achieved via a URL in the languagefile parameter in the addnews.php file. However, it has been observed that languageFile is defined before use, which may affect the vulnerability's impact.
Recommendations For gCards version 1.13, consider restricting access to the addnews.php file or the languagefile parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the languagefile parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2006-5255

Affected Products

Gcards