Product
An unauthenticated SQL injection vulnerability in the /welcome.php file of Assessment Management 1.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter.