This document describes SQL injection and authentication bypass vulnerabilities in ACollab 1.2. It provides exploitation vectors for both issues, including SQL injection via the 'login' and 'password' parameters and an authentication bypass using a crafted username.