VulnerabilityModified
CVE-2009-4238
Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php.
MEDIUM 6.5EPSS 1.08%
Does this matter?
Lower severity and a low EPSS score (1.08%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.08% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- teamst/testlink
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2009-12/0221.html
- http://osvdb.org/60919
- http://osvdb.org/60920
- http://www.coresecurity.com/content/testlink-multiple-injection-vulnerabilitiesExploit
- http://www.securityfocus.com/bid/37258Exploit
- http://www.teamst.org/index.php?option=com_content&task=view&id=84&Itemid=2Patch, Vendor Advisory, URL Repurposed
- http://archives.neohapsis.com/archives/fulldisclosure/2009-12/0221.html
- http://osvdb.org/60919
- http://osvdb.org/60920
- http://www.coresecurity.com/content/testlink-multiple-injection-vulnerabilitiesExploit
- http://www.securityfocus.com/bid/37258Exploit
- http://www.teamst.org/index.php?option=com_content&task=view&id=84&Itemid=2Patch, Vendor Advisory, URL Repurposed
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.