CVE Vulnerabilities

CVE-2006-2688

Published: May 31, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector parameter.

Affected Software

Name Vendor Start Version End Version
Achievo Achievo 1.1.0 (including) 1.1.0 (including)
Achievo Achievo 1.2.0 (including) 1.2.0 (including)

References