Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.Referenceshttp://www.securityfocus.com/archive/1/422265/100/0/threadedhttps://archive.cert.uni-stuttgart.de/bugtraq/2006/01/msg00343.htmlhttp://www.securityfocus.com/bid/16300http://secunia.com/advisories/18541http://www.vupen.com/english/advisories/2006/0254