First published: Mon Aug 24 2009(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-xoops | <=1.08 | |
E-xoops | =1.05-r3 | |
E-xoops | =1.05-rev1 | |
E-xoops | =1.05-rev2 | |
E-xoops | =1.05-rev3 | |
Bcoos | =0.20 | |
Bcoos | =3.0 | |
Bcoos | <=1.1.11 | |
Bcoos | =1.0.9 | |
Bcoos | =1.0.10 | |
Bcoos | =1.0.11 | |
Bcoos | =1.0.12 | |
Bcoos | =1.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-7036 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2008-7036, update to the latest version of the affected software that addresses these vulnerabilities.
CVE-2008-7036 affects bcoos versions up to 1.1.11 and E-XooPS versions up to 1.0.8.
CVE-2008-7036 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Any user or administrator using the vulnerable versions of the bcoos or E-XooPS software can be affected by CVE-2008-7036.