Skip to content
Noroxi

testlink records

27 published records for vendor testlink.

All records

27 records
  • An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uplo

    HighCVSS 8.8Proof of conceptEPSS 16%

    testlink · testlinkApr 3, 2020

  • A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    testlink · testlinkApr 3, 2020

  • A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency param

    CriticalCVSS 9.8No exploitEPSS 2%

    testlink · testlinkApr 3, 2020

  • TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 1%

    testlink · testlinkNov 15, 2007

  • CVE-2015-7390
    39Monitor

    SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to

    CriticalCVSS 9.8No exploitEPSS 2%

    testlink · testlinkSep 26, 2017

  • In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is

    CriticalCVSS 9.8No exploitEPSS 1%

    testlink · testlinkApr 27, 2020

  • CVE-2014-5308
    37Monitor

    Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) nam

    CriticalCVSS 9.0Proof of conceptEPSS 4%

    testlink · testlinkOct 8, 2014

  • Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via th

    HighCVSS 8.8No exploitEPSS 2%

    testlink · testlinkMar 5, 2020

  • CVE-2020-8841
    35Monitor

    An issue was discovered in TestLink 1.9.19.

    HighCVSS 8.8No exploitEPSS 1%

    testlink · testlinkFeb 10, 2020

  • TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

    HighCVSS 8.8No exploitEPSS 1%

    testlink · testlinkSep 20, 2022

  • CVE-2018-7466
    32Monitor

    install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN

    HighCVSS 7.5Proof of conceptEPSS 6%

    testlink · testlinkFeb 25, 2018

  • TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section.

    HighCVSS 8.1No exploitEPSS 0%

    testlink · testlinkSep 27, 2024

  • CVE-2014-8081
    31Monitor

    lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitra

    HighCVSS 7.5No exploitEPSS 4%

    testlink · testlinkOct 31, 2014

  • CVE-2018-7668
    30Monitor

    TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload

    HighCVSS 7.5No exploitEPSS 1%

    testlink · testlinkMar 5, 2018

  • In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.

    HighCVSS 7.5No exploitEPSS 1%

    testlink · testlinkApr 27, 2020

  • TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.

    HighCVSS 7.5No exploitEPSS 1%

    testlink · testlinkDec 30, 2023

  • CVE-2012-0938
    28Monitor

    Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to e

    MediumCVSS 6.5WeaponizedEPSS 6%

    testlink · testlinkAug 14, 2014

  • TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php

    HighCVSS 7.2No exploitEPSS 1%

    testlink · testlinkSep 16, 2022

  • TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

    HighCVSS 7.2No exploitEPSS 1%

    testlink · testlinkSep 16, 2022

  • CVE-2012-0939
    26Monitor

    Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission

    MediumCVSS 6.5No exploitEPSS 1%

    testlink · testlinkAug 14, 2014

  • TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    testlink · testlinkJan 20, 2020

  • TestLink 1.9.19 has XSS via the error.php message parameter.

    MediumCVSS 6.1No exploitEPSS 1%

    testlink · testlinkAug 1, 2019

  • TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/

    MediumCVSS 6.1No exploitEPSS 1%

    testlink · testlinkDec 1, 2019

  • CVE-2015-7391
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML

    MediumCVSS 6.1No exploitEPSS 1%

    testlink · testlinkSep 26, 2017

  • TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.

    MediumCVSS 6.1No exploitEPSS 0%

    testlink · testlinkAug 26, 2024