
CVE-2006-2688
https://notcve.org/view.php?id=CVE-2006-2688
31 May 2006 — SQL injection vulnerability in the employees node (class.employee.inc) in Achievo 1.1.0 and earlier and 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the atkselector parameter. • http://bugzilla.achievo.org/show_bug.cgi?id=624 •

CVE-2002-1435 – Achievo 0.7/0.8/0.9 - Remote File Inclusion / Command Execution
https://notcve.org/view.php?id=CVE-2002-1435
11 Apr 2003 — class.atkdateattribute.js.php in Achievo 0.7.0 through 0.9.1, except 0.8.2, allows remote attackers to execute arbitrary PHP code when the 'allow_url_fopen' setting is enabled via a URL in the config_atkroot parameter that points to the code. class.atkdateattribute.js.php en Achievo 0.7.0 hasta 0.9.1 excepto 0.8.2, permite que atacantes remotos ejecuten código PHP arbitrario cuando la opción "allow_url_fopen" está establecida mediante URL en el parámetro config_atkroot que apunta al código. • https://www.exploit-db.com/exploits/21745 •