6.8
CVSSv2

CVE-2008-5877

Published: 08/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and previous versions, when magic_quotes_gpc is disabled, allow remote malicious users to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) form_id parameter to pcw/processforms.php, (3) pcwlogin and (4) pcw_pass parameters to pcw/setlogin.php, (5) searchvalue parameter to pcw/downloads.php, and the (6) searchvalue and (7) whichfield parameter to pcw/downloads.php, a different vector than CVE-2006-0444.

Vulnerable Product Search on Vulmon Subscribe to Product

phpclanwebsite phpclanwebsite 1.23.1

phpclanwebsite phpclanwebsite 1.22

phpclanwebsite phpclanwebsite 1.23.2

phpclanwebsite phpclanwebsite

phpclanwebsite phpclanwebsite 1.20

phpclanwebsite phpclanwebsite 1.21

phpclanwebsite phpclanwebsite 1.23

Exploits

Phpclanwebsite <= 1233 Fix Pack #5 (File Including/SQL/XSS) Multiple Remote Vulnerabilities The description: The set vulnerability in CMS Phpclanwebsite versions 1233 Fix Pack #5 and more low was revealed 1 Multiple File Including Vulnerabilities Vulnerability exists for the reason that direct access to some files, around logicians of w ...