Page 2 of 14 results (0.002 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 3

23 Oct 2014 — lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which reveals the installation path in an error message. lib/functions/database.class.php en TestLink anterior a 1.9.13 permite a atacantes remotos obtener información sensible a través de vectores no especificados, lo que revela la ruta de instalación en un mensaje de error. TestLink versions 1.9.12 and below suffer from a path disclosure weakness. • http://karmainsecurity.com/KIS-2014-12 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 8.8EPSS: 29%CPEs: 2EXPL: 0

14 Aug 2014 — Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfield_id parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) plan_id parameter in a create action to lib/plan/planMilestonesEdit.php; or the req_... • http://archives.neohapsis.com/archives/bugtraq/2012-02/0104.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

14 Aug 2014 — Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission to execute arbitrary SQL commands via the req_spec_id parameter to (1) reqSpecAnalyse.php, (2) reqSpecPrint.php, or (3) reqSpecView.php in requirements/. NOTE: some of these details are obtained from third party information. Múltiples vulnerabilidades de inyección SQL en TestLink 1.8.5b y anteriores permiten a usuarios remotos autenticados con el permiso de visualizació... • http://archives.neohapsis.com/archives/bugtraq/2012-02/0104.html • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 17EXPL: 8

15 Sep 2012 — Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijack the authentication of users for requests that add, delete, or modify sensitive information, as demonstrated by changing the administrator's email via an editUser action to lib/usermanagement/userInfo.php. Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en TestLink v1.9.3 y anteriores permite a atacantes remotos secuestrar la autenticación de los usuarios para petici... • https://www.exploit-db.com/exploits/21135 • CWE-352: Cross-Site Request Forgery (CSRF) •