VYPR
Vendor

webchess

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2023-39851CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.

  • CVE-2019-20896CriJul 7, 2020
    risk 0.64cvss 9.8epss 0.01

    WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.

  • CVE-2023-22959HigJan 11, 2023
    risk 0.58cvss 8.8epss 0.14

    WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).