HIGH
SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php
Published Jun 30, 2010
7.5
HIGHCVSS 2.0
EPSS 1.26%
Description
SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.
Affected products
No data.
OR
- ≤ 0.6.3
- 0.1
- 0.1.2
- 0.1.3
- 0.1.4
- 0.2.0
- 0.2.1
- 0.2.2
- 0.3.0
- 0.3.1
- 0.3.2
- 0.4.0
- 0.4.1
- 0.4.2
- 0.5.0
- 0.5.1
- 0.5.2
- 0.5.3
- 0.5.4
- 0.5.5
- 0.5.6
- 0.5.7
- 0.6.0
- 0.6.1
- 0.6.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://osvdb.org/65847 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/40025 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/secunia_research/2010-79/ x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/archive/1/512077/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/41218 vdb-entryx_refsource_BID
- http://www.taskfreak.com/original/versions x_refsource_CONFIRMPatch
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/65847 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/40025 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/secunia_research/2010-79/ | x_refsource_MISCVendor Advisory | |
| http://www.securityfocus.com/archive/1/512077/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/41218 | vdb-entryx_refsource_BID | |
| http://www.taskfreak.com/original/versions | x_refsource_CONFIRMPatch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner flexera
Published Jun 30, 2010
Updated Aug 7, 2024
Reserved Apr 26, 2010
Link CVE-2010-1521
CISA Vulnrichment
Updated n/a