Total vulnerabilities in the database
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.
Software | From | Fixed in |
---|---|---|
e-xoops / e-xoops | - | 1.08.x |
e-xoops / e-xoops | 1.05-rev1 | 1.05-rev1.x |
e-xoops / e-xoops | 1.05-rev3 | 1.05-rev3.x |
e-xoops / e-xoops | 1.05-r3 | 1.05-r3.x |
e-xoops / e-xoops | 1.05-rev2 | 1.05-rev2.x |
bcoos / devtracker | 0.20 | 0.20.x |
bcoos / devtracker | 3.0 | 3.0.x |
bcoos / bcoos | - | 1.1.11.x |
bcoos / bcoos | 1.0.9 | 1.0.9.x |
bcoos / bcoos | 1.0.10 | 1.0.10.x |
bcoos / bcoos | 1.0.11 | 1.0.11.x |
bcoos / bcoos | 1.0.12 | 1.0.12.x |
bcoos / bcoos | 1.0.13 | 1.0.13.x |