E Xoops
Vendor:
First CVE: Mar 28, 2005 · Active for 21 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact E Xoops over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2005
21 years ago
Most Recent CVE
Aug 24, 2009
6,178 days ago
CVE Severity & Scoring
E Xoops7 CVEs
71%
29%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6380HIGH Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to (a) | Dec 15, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-0828MEDIUM highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allows remote attackers to read arbitrary PHP | May 2, 2005 | 5.0 | 27 | NO | YES |
CVE-2008-7036MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier, and DevTracker module 0.20 for E-XooPS 1.0.8 and earlier, al | Aug 24, 2009 | 4.3 | 21 | NO | YES |
CVE-2005-0911HIGH Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter | Mar 28, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-0827MEDIUM Viewcat.php in (1) RUNCMS 1.1A, (2) Ciamos 0.9.2 RC1, e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops), allow remote attackers to obtain sensitive informati | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-1031MEDIUM RUNCMS 1.1A, and possibly other products based on e-Xoops (exoops), when "Allow custom avatar upload" is enabled, does not properly verify uploaded files, which allows remote attac | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-0910MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) t | May 2, 2005 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
42.9% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For E Xoops
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.08 | 1 | 7.5 | 0.9% | 0 | 1 |
| 1.05_rev3 | 2 | 6.3 | 1.1% | 0 | 1 |
| 1.05_rev2 | 1 | 7.5 | 0.9% | 0 | 1 |
| 1.05_rev1 | 1 | 7.5 | 0.9% | 0 | 1 |
| 1.05r3 | 2 | 5.0 | 5.3% | 0 | 1 |
| 1.05 | 1 | 4.3 | 1.5% | 0 | 1 |