Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 04:49:58 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1510414553&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1006-advisories%2Fsecunia-taskfreak.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1510414553.1338180598.1338180598.1338180598.1%3B%2B__utmz%3D32867617.1338180598.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) TaskFreak 0.6.3 SQL Injection http://packetstormsecurity.org/files/91296/secunia-taskfreak.txt http://packetstormsecurity.org/files/91296/secunia-taskfreak.txt http://packetstormsecurity.org/files/91296/TaskFreak-0.6.3-SQL-Injection.html Wed, 30 Jun 2010 02:56:33 GMT Secunia Research has discovered a vulnerability in TaskFreak, which can be exploited by malicious people to conduct SQL injection attacks. Input passed via the "password" parameter to login.php (when "username" is set to a valid user) is not properly sanitized before being used in a SQL query in include/classes/tzn_user.php. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code. Successful exploitation allows bypassing the authentication mechanism, but requires that "magic_quotes_gpc" is disabled. Version 0.6.3 is affected.