CVE-2009-4238

TestLink - Authenticated SQL Injection via Test Case ID or logLevel Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-4238. PoCs published by Core Security.

AI-analyzed exploit summary This advisory details multiple XSS and SQL injection vulnerabilities in TestLink versions up to 1.8.4. It includes proof-of-concept URLs demonstrating unauthenticated and authenticated exploitation scenarios.

Description

Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Core Security · textwebappsphp
https://www.exploit-db.com/exploits/10364

This advisory details multiple XSS and SQL injection vulnerabilities in TestLink versions up to 1.8.4. It includes proof-of-concept URLs demonstrating unauthenticated and authenticated exploitation scenarios.

Classification
Writeup 100%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Reliable
Target: TestLink 1.8.0-1.8.4
No auth needed
Prerequisites: Network access to TestLink instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37258
Patch, Vendor Advisory, URL Repurposed x_refsource_confirm
http://www.teamst.org/index.php?option=com_content&task=view&id=84&Itemid=2
Third Party Advisory mailing-list x_refsource_fulldisc
http://archives.neohapsis.com/archives/fulldisclosure/2009-12/0221.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/60919
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/60920

Scores

EPSS 0.0108
EPSS Percentile 60.8%

Details

CWE
CWE-89
Status published
Products (11)
teamst/testlink 1.7
teamst/testlink 1.7.1
teamst/testlink 1.7.2
teamst/testlink 1.7.3
teamst/testlink 1.7.4
teamst/testlink 1.8 (5 CPE variants)
teamst/testlink 1.8.0
teamst/testlink 1.8.1
teamst/testlink 1.8.2
teamst/testlink 1.8.3
... and 1 more
Published Dec 10, 2009
Tracked Since Feb 18, 2026