Ghlab's footprint is centered on a Korean web-based collaboration platform, GhBoard, where the observed vulnerability pattern reflects application-layer input handling and code-generation risks. The recurring weakness classes—improper input validation, code injection, and path traversal—are characteristic of web applications that parse user-supplied input and construct dynamic code or file paths without sufficient sanitization. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ghlab over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5737HIGH Unrestricted file upload vulnerability in component/upload.jsp in Korean GHBoard allows remote attackers to upload arbitrary files via unspecified vectors, probably involving a dir | Oct 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-5739MEDIUM Directory traversal vulnerability in component/flashupload/download.jsp in the FlashUpload component in Korean GHBoard allows remote attackers to read arbitrary files via a .. (dot | Oct 30, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-5738MEDIUM The FlashUpload component in Korean GHBoard uses a client-side protection mechanism to prevent uploading of dangerous file extensions, which allows remote attackers to bypass restr | Oct 30, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ghlab.
Media articles that mention a CVE ID that affects a product developed by Ghlab — matched by CVE ID, not by vendor name.