Description
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) direction and (2) order_by parameters.
Affected products
- bcoos / bcoos1.0.9 – 1.0.9
- bcoos / bcoos1.1.11
- bcoos / bcoos1.0.12 – 1.0.12
- bcoos / bcoos1.0.11 – 1.0.11
- bcoos / bcoos1.0.10 – 1.0.10
- bcoos / bcoos1.0.13 – 1.0.13
- bcoos / devtracker3.0 – 3.0
- bcoos / devtracker0.20 – 0.20
- e-xoops / e-xoops1.08
- e-xoops / e-xoops1.05 – 1.05
- e-xoops / e-xoops1.05 – 1.05
- e-xoops / e-xoops1.05 – 1.05
- e-xoops / e-xoops1.05 – 1.05