CVE-2007-2971

Publication date

2007-06-01 01:00:00

Family

mitre

State

PUBLISHED

Description

SQL injection vulnerability in getnewsitem.php in gCards 1.46 and earlier allows remote attackers to execute arbitrary SQL commands via the newsid parameter.