CVE-2009-4238
TestLink - Authenticated SQL Injection via Test Case ID or logLevel Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4238. PoCs published by Core Security.
AI-analyzed exploit summary This advisory details multiple XSS and SQL injection vulnerabilities in TestLink versions up to 1.8.4. It includes proof-of-concept URLs demonstrating unauthenticated and authenticated exploitation scenarios.
Description
Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php.
Exploits (1)
This advisory details multiple XSS and SQL injection vulnerabilities in TestLink versions up to 1.8.4. It includes proof-of-concept URLs demonstrating unauthenticated and authenticated exploitation scenarios.