
CVE-2014-8082 – TestLink 1.9.12 Path Disclosure
https://notcve.org/view.php?id=CVE-2014-8082
23 Oct 2014 — lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message. lib/functions/database.class.php en TestLink anterior a 1.9.13 permite a atacantes remotos obtener información sensible a través de vectores no especificados, lo que revela la ruta de instalación en un mensaje de error. TestLink versions 1.9.12 and below suffer from a path disclosure weakness. • http://karmainsecurity.com/KIS-2014-12 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2012-2275 – TestLink 1.9.3 - Cross-Site Request Forgery
https://notcve.org/view.php?id=CVE-2012-2275
15 Sep 2012 — Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator's email via an editUser action to lib/usermanagement/userInfo.php. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en TestLink v1.9.3 y anteriores permite a atacantes remotos secuestrar la autenticación de los usuarios para petici... • https://www.exploit-db.com/exploits/21135 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2009-4238 – TestLink Test Management and Execution System - Multiple Cross-Site Scripting / Injection Vulnerabilities
https://notcve.org/view.php?id=CVE-2009-4238
10 Dec 2009 — Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php. Múltiples vulnerabilidades de inyección SQL en TestLink en versiones anteriores a v1.8.5 permite a usuarios remotos autenticados ejecutar comandos SQL arbitrarios a través de (1) el campo "ID de caso de prueba" a lib/general/navBar.php o (2) el parámetro "logLeve... • https://www.exploit-db.com/exploits/10364 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2009-4237 – TestLink Test Management and Execution System - Multiple Cross-Site Scripting / Injection Vulnerabilities
https://notcve.org/view.php?id=CVE-2009-4237
10 Dec 2009 — Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the req parameter to login.php, and allow remote authenticated users to inject arbitrary web script or HTML via (2) the key parameter to lib/general/staticPage.php, (3) the tableName parameter to lib/attachments/attachmentupload.php, or the (4) startDate, (5) endDate, or (6) logLevel parameter to lib/events/eventviewer.php; (7) the search_notes_string parameter t... • https://www.exploit-db.com/exploits/10364 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •