Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Achievo MEDIUM 6.5
CVE-2012-5865

SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid p…

No fix yet
Fix from $1,600 2014-10-20
Achievo MEDIUM 5.0
CVE-2011-3697

Achievo 1.4.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an …

No fix yet
Fix from $1,600 2011-09-23
Achievo HIGH 7.5
CVE-2009-2734

SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote attackers to execute arbitrary …

Fix: after 1.3.4
Fix from $1,950 2009-10-16
Achievo HIGH 7.5
CVE-2009-3705EPSS 10%

PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in th…

Fix: after 1.3.4
Fix from $1,950 2009-10-16
Achievo HIGH 7.5
CVE-2008-2742

Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 th…

No fix yet
Fix from $1,950 2008-06-17
Achievo HIGH 10.0
CVE-2007-2736

PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the config_a…

No fix yet
Fix from $1,950 2007-05-17
Achievo MEDIUM 6.4
CVE-2006-2688

SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to ex…

Patch available
Fix from $1,600 2006-05-31
Achievo HIGH 7.5
CVE-2002-1435EPSS 7%

class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url…

Patch available
Fix from $1,950 2003-04-11