Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat parameter to index.php.
| Software | From | Fixed in |
|---|---|---|
| e-xoops / e-xoops | - | - |