
CVE-2023-32637
https://notcve.org/view.php?id=CVE-2023-32637
25 Jul 2023 — GBrowse accepts files with any formats uploaded and places them in the area accessible through unauthenticated web requests. Therefore, anyone who can upload files through the product may execute arbitrary code on the server. • http://gmod.org/wiki/GBrowse • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2008-3781
https://notcve.org/view.php?id=CVE-2008-3781
26 Aug 2008 — Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en GMOD GBrowse anterior a 1.69, permite a atacantes remotos inyectar secuencias de comandos Web o HTML de su elección a través de vectores no especificados. • http://gmod.org/wiki/GMOD_News#GBrowse_1.69_Released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •