Clever Copy is a focused web application product that sits in the vulnerability landscape as a moderately active target. Its disclosures center on application-layer input-handling weaknesses—SQL injection and cross-site scripting—that are characteristic of web-facing software, and a moderate tendency toward public exploit availability has historically marked this product class. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clever Copy over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0583HIGH SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Feb 8, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-2323HIGH Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id par | Jul 19, 2005 | 7.5 | 29 | NO | YES |
CVE-2008-2909HIGH SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter. | Jun 30, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-1718MEDIUM Magus Perde Clever Copy 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to view the database usernam | Apr 11, 2006 | 5.0 | 25 | NO | YES |
CVE-2005-2324MEDIUM Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype or searchterm parameters to ( | Jul 19, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-2326MEDIUM Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php. | Jul 19, 2005 | 4.3 | 21 | NO | YES |
CVE-2008-1608HIGH SQL injection vulnerability in postview.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter, a different vector than CVE-2008-0363 | Apr 1, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-0363HIGH Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the ( | Jan 18, 2008 | 7.5 | 19 | NO | NO |
CVE-2005-2325MEDIUM Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5 | Jul 19, 2005 | 5.0 | 15 | NO | NO |
CVE-2008-0362MEDIUM Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter. | Jan 18, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clever Copy.
Media articles that mention a CVE ID that affects a product developed by Clever Copy — matched by CVE ID, not by vendor name.