SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter (aka user_id variable) to dispatch.php.
| Software | From | Fixed in |
|---|---|---|
| achievo / achievo | 1.2.0 | 1.2.0.x |
| achievo / achievo | 1.0.1 | 1.0.1.x |
| achievo / achievo | 1.3.2 | 1.3.2.x |
| achievo / achievo | 1.3.1 | 1.3.1.x |
| achievo / achievo | 1.1.0-rc3 | 1.1.0-rc3.x |
| achievo / achievo | 0.7.1 | 0.7.1.x |
| achievo / achievo | 0.8.0_rc1 | 0.8.0_rc1.x |
| achievo / achievo | 0.8.0 | 0.8.0.x |
| achievo / achievo | 0.8.1 | 0.8.1.x |
| achievo / achievo | 1.0.0 | 1.0.0.x |
| achievo / achievo | 1.3.3 | 1.3.3.x |
| achievo / achievo | 1.2.1 | 1.2.1.x |
| achievo / achievo | 1.2.0-rc1 | 1.2.0-rc1.x |
| achievo / achievo | 0.8.0_rc2 | 0.8.0_rc2.x |
| achievo / achievo | 1.0.2 | 1.0.2.x |
| achievo / achievo | 1.3.0-rc1 | 1.3.0-rc1.x |
| achievo / achievo | 0.7.2 | 0.7.2.x |
| achievo / achievo | 1.0.0-rc3 | 1.0.0-rc3.x |
| achievo / achievo | 1.1.0-rc2 | 1.1.0-rc2.x |
| achievo / achievo | 0.9.1 | 0.9.1.x |
| achievo / achievo | 1.0.3 | 1.0.3.x |
| achievo / achievo | 1.0.4 | 1.0.4.x |
| achievo / achievo | 1.0.0-rc2 | 1.0.0-rc2.x |
| achievo / achievo | - | 1.3.4.x |
| achievo / achievo | 0.7.3 | 0.7.3.x |
| achievo / achievo | 1.1.0-rc1 | 1.1.0-rc1.x |
| achievo / achievo | 1.3.0 | 1.3.0.x |
| achievo / achievo | 1.1.0 | 1.1.0.x |
| achievo / achievo | 0.9.0 | 0.9.0.x |
| achievo / achievo | 0.7.0 | 0.7.0.x |
| achievo / achievo | 1.3.0-rc2 | 1.3.0-rc2.x |
| achievo / achievo | 1.0.0-rc1 | 1.0.0-rc1.x |