CVE-2008-7036
24.08.2009, 10:30
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.
Vendor | Product | Version |
---|---|---|
e-xoops | e-xoops | 𝑥 ≤ 1.08 |
e-xoops | e-xoops | 1.05:r3 |
e-xoops | e-xoops | 1.05:rev1 |
e-xoops | e-xoops | 1.05:rev2 |
e-xoops | e-xoops | 1.05:rev3 |
bcoos | devtracker | 0.20 |
bcoos | devtracker | 3.0 |
bcoos | bcoos | 𝑥 ≤ 1.1.11 |
bcoos | bcoos | 1.0.9 |
bcoos | bcoos | 1.0.10 |
bcoos | bcoos | 1.0.11 |
bcoos | bcoos | 1.0.12 |
bcoos | bcoos | 1.0.13 |
𝑥
= Vulnerable software versions
References