vendor:
TestLink
by:
Jerzy Kramarz
7,5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: TestLink
Affected Version From: 1.9.11
Affected Version To: 1.9.11
Patch Exists: YES
Related CWE: CVE-2014-5308
CPE: a:testlink:testlink:1.9.11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Multiple SQL Injection Vulnerabilities in TestLink
Two SQL injection vulnerabilities have been found and confirmed within the software as an authenticated user. A successful attack could allow an authenticated attacker to access information such as usernames and password hashes that are stored in the database. The following URLs and parameters have been confirmed to suffer from Multiple SQL injections: Vulnerability 1 (Fixed in commit #7a09973 in official repository) and Vulnerability 2 (Fixed in patches after commit #7a09973 in official repository)
Mitigation:
The vulnerabilities have been fixed in SVN commit number 7a09973 and patches after commit #7a09973 in official repository.