admin/contest.php in Weekly Drawing Contest 0.0.1 allows remote attackers to bypass authentication, and insert new contest information into a database, via a direct POST request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Weekly_drawing_contest | Weekly_drawing_contest | 0.0.1 (including) | 0.0.1 (including) |