Записи testlink
27 опубликованных записей вендора testlink.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3,7 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-8639Proof of concept | An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uplotestlink · testlink · CWE-434 | Высокая8,8 | — | 15,9 % | 3 апр. 2020 г. |
40В плане | CVE-2020-8637Proof of concept | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_idtestlink · testlink · CWE-89 | Критическая9,8 | — | 2,9 % | 3 апр. 2020 г. |
40В плане | CVE-2020-8638Эксплойта нет | A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency paramtestlink · testlink · CWE-89 | Критическая9,8 | — | 1,7 % | 3 апр. 2020 г. |
40В плане | CVE-2007-6006Эксплойта нет | TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.testlink · testlink · CWE-287 | Критическая10,0 | — | 1,4 % | 15 нояб. 2007 г. |
39Наблюдать | CVE-2015-7390Эксплойта нет | SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to testlink · testlink · CWE-89 | Критическая9,8 | — | 1,6 % | 26 сент. 2017 г. |
39Наблюдать | CVE-2020-12274Эксплойта нет | In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is testlink · testlink | Критическая9,8 | — | 1,2 % | 27 апр. 2020 г. |
37Наблюдать | CVE-2014-5308Proof of concept | Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) namtestlink · testlink · CWE-89 | Критическая9,0 | — | 3,5 % | 8 окт. 2014 г. |
36Наблюдать | CVE-2019-20107Эксплойта нет | Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via thtestlink · testlink · CWE-89 | Высокая8,8 | — | 2,0 % | 5 мар. 2020 г. |
35Наблюдать | CVE-2020-8841Эксплойта нет | An issue was discovered in TestLink 1.9.19.testlink · testlink · CWE-89 | Высокая8,8 | — | 1,4 % | 10 февр. 2020 г. |
35Наблюдать | CVE-2022-35196Эксплойта нет | TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.testlink · testlink · CWE-352 | Высокая8,8 | — | 0,5 % | 20 сент. 2022 г. |
32Наблюдать | CVE-2018-7466Proof of concept | install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGINtestlink · testlink · CWE-94 | Высокая7,5 | — | 6,1 % | 25 февр. 2018 г. |
32Наблюдать | CVE-2024-46097Эксплойта нет | TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section.testlink · testlink · CWE-284 | Высокая8,1 | — | 0,4 % | 27 сент. 2024 г. |
31Наблюдать | CVE-2014-8081Эксплойта нет | lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitratestlink · testlink · CWE-94 | Высокая7,5 | — | 4,2 % | 31 окт. 2014 г. |
30Наблюдать | CVE-2018-7668Эксплойта нет | TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownloadtestlink · testlink · CWE-200 | Высокая7,5 | — | 1,5 % | 5 мар. 2018 г. |
30Наблюдать | CVE-2020-12273Эксплойта нет | In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.testlink · testlink · CWE-311 | Высокая7,5 | — | 0,8 % | 27 апр. 2020 г. |
30Наблюдать | CVE-2023-50110Эксплойта нет | TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.testlink · testlink | Высокая7,5 | — | 0,7 % | 30 дек. 2023 г. |
28Наблюдать | CVE-2012-0938Готовый эксплойт | Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to etestlink · testlink · CWE-89 | Средняя6,5 | — | 5,8 % | 14 авг. 2014 г. |
28Наблюдать | CVE-2022-35195Эксплойта нет | TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.phptestlink · testlink | Высокая7,2 | — | 1,3 % | 16 сент. 2022 г. |
28Наблюдать | CVE-2022-35193Эксплойта нет | TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.testlink · testlink · CWE-89 | Высокая7,2 | — | 1,2 % | 16 сент. 2022 г. |
26Наблюдать | CVE-2012-0939Эксплойта нет | Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission testlink · testlink · CWE-89 | Средняя6,5 | — | 1,2 % | 14 авг. 2014 г. |
24Наблюдать | CVE-2019-20381Эксплойта нет | TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter.testlink · testlink · CWE-79 | Средняя6,1 | — | 1,0 % | 20 янв. 2020 г. |
24Наблюдать | CVE-2019-14471Эксплойта нет | TestLink 1.9.19 has XSS via the error.php message parameter.testlink · testlink · CWE-79 | Средняя6,1 | — | 0,9 % | 1 авг. 2019 г. |
24Наблюдать | CVE-2019-19491Эксплойта нет | TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/testlink · testlink · CWE-79 | Средняя6,1 | — | 0,8 % | 1 дек. 2019 г. |
24Наблюдать | CVE-2015-7391Эксплойта нет | Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML testlink · testlink · CWE-79 | Средняя6,1 | — | 0,8 % | 26 сент. 2017 г. |
24Наблюдать | CVE-2024-42906Эксплойта нет | TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.testlink · testlink · CWE-79 | Средняя6,1 | — | 0,3 % | 26 авг. 2024 г. |
- CVE-2020-863940В плане
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uplo
ВысокаяCVSS 8,8Proof of conceptEPSS 16 %testlink · testlink3 апр. 2020 г.
- CVE-2020-863740В плане
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id
КритическаяCVSS 9,8Proof of conceptEPSS 3 %testlink · testlink3 апр. 2020 г.
- CVE-2020-863840В плане
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency param
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %testlink · testlink3 апр. 2020 г.
- CVE-2007-600640В плане
TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %testlink · testlink15 нояб. 2007 г.
- CVE-2015-739039Наблюдать
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %testlink · testlink26 сент. 2017 г.
- CVE-2020-1227439Наблюдать
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %testlink · testlink27 апр. 2020 г.
- CVE-2014-530837Наблюдать
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) nam
КритическаяCVSS 9,0Proof of conceptEPSS 4 %testlink · testlink8 окт. 2014 г.
- CVE-2019-2010736Наблюдать
Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via th
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %testlink · testlink5 мар. 2020 г.
- CVE-2020-884135Наблюдать
An issue was discovered in TestLink 1.9.19.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %testlink · testlink10 февр. 2020 г.
- CVE-2022-3519635Наблюдать
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %testlink · testlink20 сент. 2022 г.
- CVE-2018-746632Наблюдать
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %testlink · testlink25 февр. 2018 г.
- CVE-2024-4609732Наблюдать
TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section.
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %testlink · testlink27 сент. 2024 г.
- CVE-2014-808131Наблюдать
lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitra
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %testlink · testlink31 окт. 2014 г.
- CVE-2018-766830Наблюдать
TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %testlink · testlink5 мар. 2018 г.
- CVE-2020-1227330Наблюдать
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %testlink · testlink27 апр. 2020 г.
- CVE-2023-5011030Наблюдать
TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %testlink · testlink30 дек. 2023 г.
- CVE-2012-093828Наблюдать
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to e
СредняяCVSS 6,5Готовый эксплойтEPSS 6 %testlink · testlink14 авг. 2014 г.
- CVE-2022-3519528Наблюдать
TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %testlink · testlink16 сент. 2022 г.
- CVE-2022-3519328Наблюдать
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %testlink · testlink16 сент. 2022 г.
- CVE-2012-093926Наблюдать
Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission
СредняяCVSS 6,5Эксплойта нетEPSS 1 %testlink · testlink14 авг. 2014 г.
- CVE-2019-2038124Наблюдать
TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %testlink · testlink20 янв. 2020 г.
- CVE-2019-1447124Наблюдать
TestLink 1.9.19 has XSS via the error.php message parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %testlink · testlink1 авг. 2019 г.
- CVE-2019-1949124Наблюдать
TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/
СредняяCVSS 6,1Эксплойта нетEPSS 1 %testlink · testlink1 дек. 2019 г.
- CVE-2015-739124Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML
СредняяCVSS 6,1Эксплойта нетEPSS 1 %testlink · testlink26 сент. 2017 г.
- CVE-2024-4290624Наблюдать
TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %testlink · testlink26 авг. 2024 г.