Title: TaskFreak! v0.6.4 Multiple Cross-Site Scripting Vulnerabilities
Advisory ID: ZSL-2011-4990
Type: Remote
Impact: Cross-Site Scripting
Risk: (3/5)
Release Date: 11.02.2011
TaskFreak! Original is a simple but efficient web based task manager written in PHP.
TaskFreak! suffers from multiple XSS vulnerabilities when parsing input to multiple parameters in different scripts. The vulnerable POST parameters are: 'sContext', 'sort', 'dir' and 'show' thru index.php. Also the GET parameters 'dir' and 'show' thru 'print_list.php' are vulnerable. Header variable 'referer' is vulnerable thru rss.php script. Attackers can exploit these weaknesses to execute arbitrary HTML and script code in a user's browser session.
Stan Ozier - http://www.taskfreak.com
Affected Version
0.6.4 (multi-user)
Tested On
MS Windows XP Pro SP3-EN, XAMPP (latest)
Vendor Status
[27.01.2011] Vulnerability discovered.
[31.01.2011] Tried contacting vendor thru their forums.
[01.02.2011] 3rd party offered to review vuln details and offered patching.
[10.02.2011] No response from vendor.
[11.02.2011] Public advisory released.
Vulnerability discovered by Gjoko Krstic - <gjoko@zeroscience.mk>
High five to Borg
[11.02.2011] - Initial release
[12.02.2011] - Added reference [2], [3] and [4]
[14.02.2011] - Added reference [5], [6] and [7]
[15.02.2011] - Added reference [8]
[17.02.2011] - Added reference [9] and [10]
[25.02.2011] - Added reference [11] and [12]
Zero Science Lab

Web: http://www.zeroscience.mk
e-mail: lab@zeroscience.mk