TROYANOSYVIRUS
Volver a CVEs

CVE-2009-2734

N/A

Descripcion

SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado10/16/2009
Ultima modificacion4/23/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

achievo:achievo

Debilidades (CWE)

CWE-89

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.