Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at getticket.php.
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at deleteticket.php.
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at saveticket.php.
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at savewinner.php via the ticketid and draw parameters.