Cross-site Scripting Vulnerabilities in DevTracker Module for Bcoos and E-XooPS
CVE-2008-7036

Currently unrated

Key Information:

Vendor

E-xoops

Vendor
CVE Published:
24 August 2009

What is CVE-2008-7036?

Multiple cross-site scripting (XSS) vulnerabilities exist in the index.php file of the DevTracker module for both bcoos and E-XooPS platforms. These vulnerabilities allow remote attackers to craft malicious web scripts by exploiting the 'direction' and 'order_by' parameters. If successfully executed, these scripts can compromise user data, hijack sessions, or redirect users to malicious sites, thereby posing significant risks to the integrity and security of the affected web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.