CVE-2010-1521

EUVD-2010-1548
SQL injection vulnerability in include/classes/tzn_user.php in TaskFreak! Original multi user before 0.6.4 allows remote attackers to execute arbitrary SQL commands via the password parameter to login.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
Affected Products (NVD)
VendorProductVersion
taskfreaktaskfreak\!
𝑥
≤ 0.6.3
taskfreaktaskfreak\!
0.1
taskfreaktaskfreak\!
0.1.2
taskfreaktaskfreak\!
0.1.3
taskfreaktaskfreak\!
0.1.4
taskfreaktaskfreak\!
0.2.0
taskfreaktaskfreak\!
0.2.1
taskfreaktaskfreak\!
0.2.2
taskfreaktaskfreak\!
0.3.0
taskfreaktaskfreak\!
0.3.1
taskfreaktaskfreak\!
0.3.2
taskfreaktaskfreak\!
0.4.0
taskfreaktaskfreak\!
0.4.1
taskfreaktaskfreak\!
0.4.2
taskfreaktaskfreak\!
0.5.0
taskfreaktaskfreak\!
0.5.1
taskfreaktaskfreak\!
0.5.2
taskfreaktaskfreak\!
0.5.3
taskfreaktaskfreak\!
0.5.4
taskfreaktaskfreak\!
0.5.5
taskfreaktaskfreak\!
0.5.6
taskfreaktaskfreak\!
0.5.7
taskfreaktaskfreak\!
0.6.0
taskfreaktaskfreak\!
0.6.1
taskfreaktaskfreak\!
0.6.2
𝑥
= Vulnerable software versions