CVE-2012-0938

TestLink <1.9.3, 1.8.5b - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfield_id parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) plan_id parameter in a create action to lib/plan/planMilestonesEdit.php; or the req_spec_id parameter to (6) reqImport.php or (7) in a create action to reqEdit.php in lib/requirements/. NOTE: some of these details are obtained from third party information.

Exploits (1)

metasploit WORKING POC EXCELLENT
by bcoles · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/testlink_upload_exec.rb

Scores

EPSS 0.2942
EPSS Percentile 96.6%

Details

CWE
CWE-89
Status published
Products (2)
testlink/testlink 1.8.5b
testlink/testlink 1.9.3
Published Aug 14, 2014
Tracked Since Feb 18, 2026