9
CVSSv2

CVE-2014-5308

Published: 08/10/2014 Updated: 09/10/2014
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

testlink testlink 1.9.11

Exploits

Vulnerability title: Multiple SQL Injection Vulnerabilities in TestLink CVE: CVE-2014-5308 Vendor: Testlink Product: TestLink Affected version: 1911 Fixed version: Fixed in SVN commit number 7a09973 Reported by: Jerzy Kramarz Details: Two SQL injection vulnerabilities have been found and confirmed within the software as an authenticated user A ...
TestLink version 1911 suffers from multiple remote SQL injection vulnerabilities ...