Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Weekly Drawing Contest Subscribe
Filtered by product Weekly Drawing Contest
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-1601 1 Weekly Drawing Contest 1 Weekly Drawing Contest 2018-10-16 5.0 MEDIUM N/A
** DISPUTED ** Directory traversal vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the order parameter. NOTE: another researcher disputes this vulnerability, noting that the order variable is not used in any context that allows opening files.
CVE-2007-1602 1 Weekly Drawing Contest 1 Weekly Drawing Contest 2018-10-16 7.5 HIGH N/A
SQL injection vulnerability in check_vote.php in Weekly Drawing Contest 0.0.1 allows remote attackers to execute arbitrary SQL commands via the order parameter.
CVE-2007-1603 1 Weekly Drawing Contest 1 Weekly Drawing Contest 2018-10-16 7.5 HIGH N/A
admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request.