← Vulnerability feed

Vulnerability record · CVE-2008-7036 · published 24 August 2009

CVE-2008-7036: E-xoops cross-site scripting vulnerability

E Xoops · E Xoops

Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.

4.3 CVSS 2.0 Medium EPSS 1.5% · top 26.8% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
10References, 8 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-7036 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-6380E-xoops sql injection vulnerabilityMultiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands v…EPSS 1.0%7.5CVE-2007-6266Bcoos sql injection vulnerabilityMultiple SQL injection vulnerabilities in bcoos 1.0.10 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the gid parameter…EPSS 1.1%7.5CVE-2007-6275Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/adresses/ratefile.php in bcoos 1.0.10 and earlier allows remote attackers to execute arbitrary SQL commands vi…EPSS 0.91%7.5CVE-2007-6080Bcoos sql injection vulnerabilitySQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers to execute arbitrary SQL comm…EPSS 1.2%7.5CVE-2007-5104Bcoos sql injection vulnerabilitySQL injection vulnerability in index.php in the Arcade module in bcoos 1.0.10 allows remote attackers to execute arbitrary SQL commands via the gid p…EPSS 1.1%7.5CVE-2005-0911E-xoops vulnerabilityMultiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.…EPSS 1.1%6.8CVE-2007-6079Bcoos path traversal vulnerabilityDirectory traversal vulnerability in include/common.php in bcoos 1.0.10 allows remote attackers to include and execute arbitrary local files via a ..…EPSS 1.9%5.0CVE-2008-2350Bcoos path traversal vulnerabilityDirectory traversal vulnerability in highlight.php in bcoos 1.0.9 through 1.0.13 allows remote attackers to read arbitrary files via (1) .. (dot dot)…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2008-7036), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.