Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
testlink testlink vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2014-8081
lib/execute/execSetResults.php in TestLink prior to 1.9.13 allows remote malicious users to conduct PHP object injection attacks and execute arbitrary PHP code via the filter_result_result parameter.
Testlink Testlink
5
CVSSv2
CVE-2014-8082
lib/functions/database.class.php in TestLink prior to 1.9.13 allows remote malicious users to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message.
Testlink Testlink
10
CVSSv2
CVE-2007-6006
TestLink prior to 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.
Testlink Testlink
7.5
CVSSv2
CVE-2015-7390
SQL injection vulnerability in TestLink prior to 1.9.14 allows remote malicious users to execute arbitrary SQL commands via the apikey parameter to lnl.php.
Testlink Testlink
4.3
CVSSv2
CVE-2015-7391
Multiple cross-site scripting (XSS) vulnerabilities in TestLink prior to 1.9.14 allow remote malicious users to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/results/tcCreatedPerUserOnTestProject.php; the (3) contain...
Testlink Testlink
NA
CVE-2023-50110
TestLink up to and including 1.9.20 allows type juggling for authentication bypass because === is not used.
Testlink Testlink
7.5
CVSSv2
CVE-2020-8637
A SQL injection vulnerability in TestLink 1.9.20 allows malicious users to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
Testlink Testlink 1.9.20
2 Github repositories
7.5
CVSSv2
CVE-2020-8638
A SQL injection vulnerability in TestLink 1.9.20 allows malicious users to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
Testlink Testlink 1.9.20
NA
CVE-2022-35195
TestLink 1.9.20 Raijin exists to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
Testlink Testlink 1.9.20
6.5
CVSSv2
CVE-2020-8639
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote malicious users to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated malicious user to upload a malicious file (containing PHP code...
Testlink Testlink 1.9.20
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »