functional security
Showing 1 - 1 of 1 RSS Feed

Files

TaskFreak 0.6.3 SQL Injection
Posted Jun 30, 2010
Site secunia.com

Secunia Research has discovered a vulnerability in TaskFreak, which can be exploited by malicious people to conduct SQL injection attacks. Input passed via the "password" parameter to login.php (when "username" is set to a valid user) is not properly sanitized before being used in a SQL query in include/classes/tzn_user.php. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation allows bypassing the authentication mechanism, but requires that "magic_quotes_gpc" is disabled. Version 0.6.3 is affected.

tags | advisory, arbitrary, php, sql injection
advisories | CVE-2010-1521
MD5 | 2563bade9296fac0c6ca234a4450cc9a
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close