CVE-2010-1521

SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
flexeraCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
taskfreaktaskfreak\!
𝑥
≤ 0.6.3
taskfreaktaskfreak\!
0.1
taskfreaktaskfreak\!
0.1.2
taskfreaktaskfreak\!
0.1.3
taskfreaktaskfreak\!
0.1.4
taskfreaktaskfreak\!
0.2.0
taskfreaktaskfreak\!
0.2.1
taskfreaktaskfreak\!
0.2.2
taskfreaktaskfreak\!
0.3.0
taskfreaktaskfreak\!
0.3.1
taskfreaktaskfreak\!
0.3.2
taskfreaktaskfreak\!
0.4.0
taskfreaktaskfreak\!
0.4.1
taskfreaktaskfreak\!
0.4.2
taskfreaktaskfreak\!
0.5.0
taskfreaktaskfreak\!
0.5.1
taskfreaktaskfreak\!
0.5.2
taskfreaktaskfreak\!
0.5.3
taskfreaktaskfreak\!
0.5.4
taskfreaktaskfreak\!
0.5.5
taskfreaktaskfreak\!
0.5.6
taskfreaktaskfreak\!
0.5.7
taskfreaktaskfreak\!
0.6.0
taskfreaktaskfreak\!
0.6.1
taskfreaktaskfreak\!
0.6.2
𝑥
= Vulnerable software versions