SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtUserName (aka User Name) parameter. NOTE: some of these details are obtained from third party information.Referenceshttp://www.exploit-db.com/exploits/9079http://www.securityfocus.com/bid/35560http://osvdb.org/55560http://secunia.com/advisories/35677