TROYANOSYVIRUS
Voltar para CVEs

CVE-2009-2734

N/A

Descricao

SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado10/16/2009
Ultima modificacao4/23/2026
Fontenvd
Avistamentos honeypot0

This product uses data from the NVD API but is not endorsed or certified by the NVD.