Phpclanwebsite operates a niche web application with a modestly represented vulnerability footprint concentrated in a single product. The exposure recurs through common web-application weakness classes including path traversal, cross-site scripting, and SQL injection, reflecting standard input-validation and output-encoding gaps in web-facing code. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpclanwebsite over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0444MEDIUM SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function | Jan 26, 2006 | 6.8 | 27 | NO | YES |
CVE-2008-5877MEDIUM Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL | Jan 8, 2009 | 6.8 | 26 | NO | YES |
CVE-2008-5878MEDIUM Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow rem | Jan 8, 2009 | 5.1 | 23 | NO | YES |
CVE-2008-5879MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via | Jan 8, 2009 | 4.3 | 21 | NO | YES |
CVE-2006-0366MEDIUM Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag. | Jan 22, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-0445MEDIUM index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\" | Jan 26, 2006 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpclanwebsite.
Media articles that mention a CVE ID that affects a product developed by Phpclanwebsite — matched by CVE ID, not by vendor name.