← Vulnerability feed

Vulnerability record · CVE-2007-6079 · published 21 November 2007

CVE-2007-6079: Bcoos path traversal vulnerability

Bcoos · Bcoos

Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file.

6.8 CVSS 2.0 Medium EPSS 1.9% · top 21.3% CWE-22 · Path traversal
6.8CVSS 2.0 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xoopsOption[pagetype] parameter to the default URI for modules/news/. NOTE: this can be leveraged by using legitimate product functionality to upload a file that contains the code, then including that file.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6079 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-6266Bcoos sql injection vulnerabilityMultiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter…EPSS 1.1%7.5CVE-2007-6275Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to execute arbitrary SQL commands vi…EPSS 0.91%7.5CVE-2007-6080Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL comm…EPSS 1.2%7.5CVE-2007-5104Bcoos sql injection vulnerabilitySQL injection vulnerability in index.php in the Arcade module in bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the gid p…EPSS 1.1%5.0CVE-2008-2350Bcoos path traversal vulnerabilityDirectory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot)…EPSS 2.7%4.6CVE-2008-6381Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses m…EPSS 1.6%4.3CVE-2008-7036E-xoops cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 fo…EPSS 1.5%4.3CVE-2007-6274Bcoos cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attack…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2007-6079), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.