CVE-2008-7036: XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) orderby parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7036?
CVE-2008-7036 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2008-7036?
To fix CVE-2008-7036, update to the latest version of the affected software that addresses these vulnerabilities.
What are the affected software versions for CVE-2008-7036?
CVE-2008-7036 affects bcoos versions up to 1.1.11 and E-XooPS versions up to 1.0.8.
What type of vulnerability is CVE-2008-7036?
CVE-2008-7036 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Who can be affected by CVE-2008-7036?
Any user or administrator using the vulnerable versions of the bcoos or E-XooPS software can be affected by CVE-2008-7036.