← Vulnerability feed

Vulnerability record · CVE-2007-6274 · published 7 December 2007

CVE-2007-6274: Bcoos cross-site scripting vulnerability

Bcoos · Bcoos

Multiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) day or (2) year parameter.

4.3 CVSS 2.0 Medium EPSS 1.1% · top 36.4% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in modules/ecal/display.php in the Event Calendar in bcoos 1.0.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) day or (2) year parameter.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6274 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-6266Bcoos sql injection vulnerabilityMultiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter…EPSS 1.1%7.5CVE-2007-6275Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to execute arbitrary SQL commands vi…EPSS 0.91%7.5CVE-2007-6080Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL comm…EPSS 1.2%7.5CVE-2007-5104Bcoos sql injection vulnerabilitySQL injection vulnerability in index.php in the Arcade module in bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the gid p…EPSS 1.1%6.8CVE-2007-6079Bcoos path traversal vulnerabilityDirectory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a ..…EPSS 1.9%5.0CVE-2008-2350Bcoos path traversal vulnerabilityDirectory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot)…EPSS 2.7%4.6CVE-2008-6381Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses m…EPSS 1.6%4.3CVE-2008-7036E-xoops cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 fo…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2007-6274), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.