7.5
CVSSv2

CVE-2010-1583

Published: 06/05/2010 Updated: 17/08/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! prior to 0.6.3, allows remote malicious users to execute arbitrary SQL commands via the username field in a login action.

Vulnerable Product Search on Vulmon Subscribe to Product

taskfreak taskfreak\\! 0.5.5

taskfreak taskfreak\\! 0.5.6

taskfreak taskfreak\\! 0.5.3

taskfreak taskfreak\\! 0.1.2

taskfreak taskfreak\\! 0.1

taskfreak taskfreak\\! 0.4.2

taskfreak taskfreak\\! 0.5.0

taskfreak taskfreak\\! 0.4.1

taskfreak taskfreak\\! 0.4.0

taskfreak taskfreak\\! 0.6.0

taskfreak taskfreak\\! 0.5.4

taskfreak taskfreak\\! 0.5.7

taskfreak taskfreak\\!

taskfreak taskfreak\\! 0.6.1

taskfreak taskfreak\\! 0.5.1

taskfreak taskfreak\\! 0.5.2

taskfreak taskfreak\\! 0.1.4

taskfreak taskfreak\\! 0.1.3

tirzen tirzen framework 1.5

Exploits

CVE-2010-1583 Vendor notified and product update released Details of this report are also available at wwwmadirishnet/?article=456 Description of Vulnerability: - ------------------------------ The Tirzen Framework (wwwtirzennet/tzn/) is a supporting API developed by Tirzen (wwwtirzencom), an intranet and internet so ...
Task Freak version 062 suffers from a remote SQL injection vulnerability that allows for authentication bypass ...