TaskFreak! Tirzen Framework 'LoadByKey()' SQL Injection Vulnerability
BID:39793
Info
TaskFreak! Tirzen Framework 'LoadByKey()' SQL Injection Vulnerability
| Bugtraq ID: | 39793 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1583 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Mad Irish |
| Vulnerable: |
Stan Ozier TaskFreak! 0.6.2 |
| Not Vulnerable: |
Stan Ozier TaskFreak! 0.6.3 |
Discussion
TaskFreak! Tirzen Framework 'LoadByKey()' SQL Injection Vulnerability
TaskFreak! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. This issue occurs in the Tirzen Framework.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TaskFreak! 0.6.2 is vulnerable; other versions may also be vulnerable.
TaskFreak! is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. This issue occurs in the Tirzen Framework.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
TaskFreak! 0.6.2 is vulnerable; other versions may also be vulnerable.
Exploit / POC
TaskFreak! Tirzen Framework 'LoadByKey()' SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
TaskFreak! Tirzen Framework 'LoadByKey()' SQL Injection Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
TaskFreak! Tirzen Framework 'LoadByKey()' SQL Injection Vulnerability
References:
References:
- TaskFreak! 0.6.2 SQL Injection Vulnerability (Mad Irish)
- TaskFreak! Homepage (Stan Ozier)
- TaskFreak! Version History (Stan Ozier)