Перейти к содержимому
Noroxi

Записи testlink

27 опубликованных записей вендора testlink.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 3,7 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

27 записей
  • CVE-2020-8639
    40В плане

    An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uplo

    ВысокаяCVSS 8,8Proof of conceptEPSS 16 %

    testlink · testlink3 апр. 2020 г.

  • CVE-2020-8637
    40В плане

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    testlink · testlink3 апр. 2020 г.

  • CVE-2020-8638
    40В плане

    A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency param

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    testlink · testlink3 апр. 2020 г.

  • CVE-2007-6006
    40В плане

    TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    testlink · testlink15 нояб. 2007 г.

  • CVE-2015-7390
    39Наблюдать

    SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    testlink · testlink26 сент. 2017 г.

  • CVE-2020-12274
    39Наблюдать

    In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    testlink · testlink27 апр. 2020 г.

  • CVE-2014-5308
    37Наблюдать

    Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) nam

    КритическаяCVSS 9,0Proof of conceptEPSS 4 %

    testlink · testlink8 окт. 2014 г.

  • CVE-2019-20107
    36Наблюдать

    Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via th

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    testlink · testlink5 мар. 2020 г.

  • CVE-2020-8841
    35Наблюдать

    An issue was discovered in TestLink 1.9.19.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    testlink · testlink10 февр. 2020 г.

  • CVE-2022-35196
    35Наблюдать

    TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    testlink · testlink20 сент. 2022 г.

  • CVE-2018-7466
    32Наблюдать

    install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN

    ВысокаяCVSS 7,5Proof of conceptEPSS 6 %

    testlink · testlink25 февр. 2018 г.

  • CVE-2024-46097
    32Наблюдать

    TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    testlink · testlink27 сент. 2024 г.

  • CVE-2014-8081
    31Наблюдать

    lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitra

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    testlink · testlink31 окт. 2014 г.

  • CVE-2018-7668
    30Наблюдать

    TestLink through 1.9.16 allows remote attackers to read arbitrary attachments via a modified ID field to /lib/attachments/attachmentdownload

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    testlink · testlink5 мар. 2018 г.

  • CVE-2020-12273
    30Наблюдать

    In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    testlink · testlink27 апр. 2020 г.

  • CVE-2023-50110
    30Наблюдать

    TestLink through 1.9.20 allows type juggling for authentication bypass because === is not used.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    testlink · testlink30 дек. 2023 г.

  • CVE-2012-0938
    28Наблюдать

    Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to e

    СредняяCVSS 6,5Готовый эксплойтEPSS 6 %

    testlink · testlink14 авг. 2014 г.

  • CVE-2022-35195
    28Наблюдать

    TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    testlink · testlink16 сент. 2022 г.

  • CVE-2022-35193
    28Наблюдать

    TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    testlink · testlink16 сент. 2022 г.

  • CVE-2012-0939
    26Наблюдать

    Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    testlink · testlink14 авг. 2014 г.

  • CVE-2019-20381
    24Наблюдать

    TestLink before 1.9.20 allows XSS via non-lowercase javascript: in the index.php reqURI parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    testlink · testlink20 янв. 2020 г.

  • CVE-2019-14471
    24Наблюдать

    TestLink 1.9.19 has XSS via the error.php message parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    testlink · testlink1 авг. 2019 г.

  • CVE-2019-19491
    24Наблюдать

    TestLink 1.9.19 has XSS via the lib/testcases/archiveData.php edit parameter, the index.php reqURI parameter, or the URI in a lib/testcases/

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    testlink · testlink1 дек. 2019 г.

  • CVE-2015-7391
    24Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    testlink · testlink26 сент. 2017 г.

  • CVE-2024-42906
    24Наблюдать

    TestLink before v.1.9.20 is vulnerable to Cross Site Scripting (XSS) via the pop-up on upload file.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    testlink · testlink26 авг. 2024 г.