2 results (0.002 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

25 Jul 2023 — GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server. • http://gmod.org/wiki/GBrowse • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 6.1EPSS: 0%CPEs: 15EXPL: 0

26 Aug 2008 — Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en GMOD GBrowse anterior a 1.69, permite a atacantes remotos inyectar secuencias de comandos Web o HTML de su elección a través de vectores no especificados. • http://gmod.org/wiki/GMOD_News#GBrowse_1.69_Released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •