6.5
CVSSv2

CVE-2009-4238

Published: 10/12/2009 Updated: 14/02/2024
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in TestLink prior to 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php.

Vulnerable Product Search on Vulmon Subscribe to Product

teamst testlink 1.7

teamst testlink 1.7.1

teamst testlink 1.8.0

teamst testlink 1.8

teamst testlink 1.7.3

teamst testlink 1.7.2

teamst testlink 1.8.3

teamst testlink 1.8.2

teamst testlink 1.8.4

teamst testlink 1.8.1

teamst testlink 1.7.4

Exploits

Core Security Technologies - CoreLabs Advisory wwwcoresecuritycom/corelabs/ Multiple XSS and Injection Vulnerabilities in TestLink Test Management and Execution System 1 *Advisory Information* Title: Multiple XSS and Injection Vulnerabilities in TestLink Test Man ...