CVE-2009-2734
16.10.2009, 16:30
SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.
Vendor | Product | Version |
---|---|---|
achievo | achievo | 𝑥 ≤ 1.3.4 |
achievo | achievo | 0.7.0 |
achievo | achievo | 0.7.1 |
achievo | achievo | 0.7.2 |
achievo | achievo | 0.7.3 |
achievo | achievo | 0.8.0 |
achievo | achievo | 0.8.0_rc1:_rc1 |
achievo | achievo | 0.8.0_rc2:_rc2 |
achievo | achievo | 0.8.1 |
achievo | achievo | 0.9.0 |
achievo | achievo | 0.9.1 |
achievo | achievo | 1.0.0 |
achievo | achievo | 1.0.0:rc1 |
achievo | achievo | 1.0.0:rc2 |
achievo | achievo | 1.0.0:rc3 |
achievo | achievo | 1.0.1 |
achievo | achievo | 1.0.2 |
achievo | achievo | 1.0.3 |
achievo | achievo | 1.0.4 |
achievo | achievo | 1.1.0 |
achievo | achievo | 1.1.0:rc1 |
achievo | achievo | 1.1.0:rc2 |
achievo | achievo | 1.1.0:rc3 |
achievo | achievo | 1.2.0 |
achievo | achievo | 1.2.0:rc1 |
achievo | achievo | 1.2.1 |
achievo | achievo | 1.3.0 |
achievo | achievo | 1.3.0:rc1 |
achievo | achievo | 1.3.0:rc2 |
achievo | achievo | 1.3.1 |
achievo | achievo | 1.3.2 |
achievo | achievo | 1.3.3 |
𝑥
= Vulnerable software versions
References