vendor:
Task Freak Multi User
by:
Justin C. Klein Keane
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Task Freak Multi User
Affected Version From: Task Freak Multi User / mySQL v0.6.2
Affected Version To: Task Freak Multi User / mySQL v0.6.2
Patch Exists: YES
Related CWE: None
CPE: a:tirzen:task_freak_multi_user:0.6.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2010
CVE-2010-1583
The Tirzen Framework (http://www.tirzen.net/tzn/) is a supporting API developed by Tirzen (http://www.tirzen.com), an intranet and internet solutions provider. The Tirzen Framework contains a SQL injection vulnerability (http://www.owasp.org/index.php/SQL_Injection). This vulnerability could allow an attacker to arbitrarily manipulate SQL strings constructed using the library. This vulnerability manifests itself most notably in the Task Freak (http://www.taskfreak.com/) open source task management software. The vulnerability can be exploited to bypass authentication and gain administrative access to the Task Freak system.
Mitigation:
Upgrade to the latest version of TaskFreak.