CVE-2012-0938
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1)…
Does this matter?
Lower severity and a low EPSS score (5.84%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfield_id parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) plan_id parameter in a create action to lib/plan/planMilestonesEdit.php; or the req_spec_id parameter to (6) reqImport.php or (7) in a create action to reqEdit.php in lib/requirements/. NOTE: some of these details are obtained from third party information.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 5.84% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- testlink/testlink
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0104.html
- http://osvdb.org/79450
- http://osvdb.org/79451
- http://osvdb.org/79452
- http://osvdb.org/79453
- http://osvdb.org/79454
- http://secunia.com/advisories/48054
- http://www.securityfocus.com/bid/52086
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73327
- http://archives.neohapsis.com/archives/bugtraq/2012-02/0104.html
- http://osvdb.org/79450
- http://osvdb.org/79451
- http://osvdb.org/79452
- http://osvdb.org/79453
- http://osvdb.org/79454
- http://secunia.com/advisories/48054
- http://www.securityfocus.com/bid/52086
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73327
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.