![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.113670 |
Category: | Web application abuses |
Title: | TestLink <= 1.9.20 Multiple Vulnerabilities |
Summary: | TestLink is prone to multiple vulnerabilities. |
Description: | Summary: TestLink is prone to multiple vulnerabilities. Vulnerability Insight: The following vulnerabilities exist: - CVE-2020-8637: SQL injection (SQLi) in dragdroptreenodes.php via the node_id parameter - CVE-2020-8638: SQL injection (SQLi) in planUrgency.php via the urgency parameter - CVE-2020-8639: Arbitrary code execution due to unrestricted file uploads in keywordsImport.php - CVE-2020-12273: A crafted login.php viewer parameter exposes cleartext credentials - CVE-2020-12274: The lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session. - CVE-2024-42906: Reflected cross-site scripting (XSS) within the file upload function. Vulnerability Impact: Successful exploitation would allow an attacker to gain complete control over the target system. Affected Software/OS: TestLink version 1.9.20 and prior. Solution: No solution was made available by the vendor. Note: Vendor states that, there is not going to be a new release and users should download the branch testlink_1_9_20_fixed which addresses those vulnerabilities. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2020-8637 https://ackcent.com/blog/testlink-1.9.20-unrestricted-file-upload-and-sql-injection/ Common Vulnerability Exposure (CVE) ID: CVE-2020-8638 Common Vulnerability Exposure (CVE) ID: CVE-2020-8639 http://packetstormsecurity.com/files/161401/TestLink-1.9.20-Shell-Upload.html Common Vulnerability Exposure (CVE) ID: CVE-2020-12273 http://mantis.testlink.org/view.php?id=8895 https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/72271ef057e6e4a95c6128973902ea646f7b5462 Common Vulnerability Exposure (CVE) ID: CVE-2020-12274 http://mantis.testlink.org/view.php?id=8894 https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/2d17cd00f981f8e8c97de34a12e368ba2a55e3d0 Common Vulnerability Exposure (CVE) ID: CVE-2024-42906 |
Copyright | Copyright (C) 2020 Greenbone AG |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |