Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
https://exchange.xforce.ibmcloud.com/vulnerabilities/73680
http://www.openwall.com/lists/oss-security/2012/04/16/7
http://www.openwall.com/lists/oss-security/2012/04/16/4
http://sourceforge.net/apps/mantisbt/tsheetx/view.php?id=122