SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.
http://packetstormsecurity.com/files/171739/Simple-Task-Managing-System-1.0-SQL-Injection.html