Clansys maintains a focused product portfolio centered on its core platform, which operates within a specialized market segment and presents a narrow but identifiable vulnerability surface. The observed disclosures cluster around classification gaps in the vulnerability taxonomy, reflecting challenges in precise categorization rather than a durable pattern of specific weakness types; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clansys over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2005HIGH Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "incl | Apr 25, 2006 | 7.5 | 36 | NO | YES |
CVE-2006-1708HIGH SQL injection vulnerability in member.php in Clansys 1.1 allows remote attackers to execute arbitrary SQL commands via the showid parameter in the member page to index.php. | Apr 11, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2368MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter. | May 15, 2006 | 5.8 | 16 | NO | NO |
CVE-2006-2367MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Clansys (aka Clanpage System) 1.0 and 1.1 allows remote attackers to inject arbitrary web script or HTML via the func param | May 15, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clansys.
Media articles that mention a CVE ID that affects a product developed by Clansys — matched by CVE ID, not by vendor name.