EIP-2026-112608
PRE-CVETestlink TestManagement and Execution System 1.8.5 - Multiple Directory Traversal Vulnerabilities
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112608. PoCs published by Prashant Khandelwal.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in TestLink's userInfo.php via manipulated POST parameters (editUser, locale) or User-Agent header, allowing unauthorized file access. It includes a functional bash script to automate the attack.
Description
Testlink TestManagement and Execution System 1.8.5 - Multiple Directory Traversal Vulnerabilities
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in TestLink's userInfo.php via manipulated POST parameters (editUser, locale) or User-Agent header, allowing unauthorized file access. It includes a functional bash script to automate the attack.