Vendor
webchess
Products
1
CVEs
3
Across products
3
Status
Private
Products
1- 3 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39851 | Cri | 0.64 | 9.8 | 0.01 | Aug 15, 2023 | webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation. | ||
| CVE-2019-20896 | Cri | 0.64 | 9.8 | 0.01 | Jul 7, 2020 | WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. | ||
| CVE-2023-22959 | Hig | 0.58 | 8.8 | 0.14 | Jan 11, 2023 | WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName). |
- risk 0.64cvss 9.8epss 0.01
webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the playerID is a session variable controlled by the server, and thus cannot be used for exploitation.
- risk 0.64cvss 9.8epss 0.01
WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter.
- risk 0.58cvss 8.8epss 0.14
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).