This is a vulnerability advisory detailing XSS, LFI, and SQL Injection vulnerabilities in Achievo 1.4.5. It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
Classification
Writeup 100%
Attack Type
Xss | Sqli | Info Leak
Complexity
Trivial
Reliability
Reliable
Target:Achievo 1.4.5 and possibly below
No auth needed
Prerequisites:Network access to the target application