CVE-2007-5738

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
30/10/2007
Last modified:
09/04/2025

Description

The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restrictions and upload arbitrary files via a modified copy of component/flashupload/upload.html.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ghlab:korean_ghboard:*:*:*:*:*:*:*:*