Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2022-35196
Disclosure Date: September 20, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.
0
Attacker Value
Unknown
CVE-2022-35194
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventoryView.php.
0
Attacker Value
Unknown
CVE-2022-35195
Disclosure Date: September 16, 2022 (last updated October 08, 2023)
TestLink 1.9.20 Raijin was discovered to contain a broken access control vulnerability at /lib/attachments/attachmentdownload.php
0
Attacker Value
Unknown
CVE-2022-35193
Disclosure Date: September 16, 2022 (last updated February 24, 2025)
TestLink v1.9.20 was discovered to contain a SQL injection vulnerability via /lib/execute/execNavigator.php.
0
Attacker Value
Unknown
CVE-2020-12274
Disclosure Date: April 27, 2020 (last updated November 27, 2024)
In TestLink 1.9.20, the lib/cfields/cfieldsExport.php goback_url parameter causes a security risk because it depends on client input and is not constrained to lib/cfields/cfieldsView.php at the web site associated with the session.
0
Attacker Value
Unknown
CVE-2020-12273
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
In TestLink 1.9.20, a crafted login.php viewer parameter exposes cleartext credentials.
0
Attacker Value
Unknown
CVE-2020-8638
Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in planUrgency.php via the urgency parameter.
0
Attacker Value
Unknown
CVE-2020-8637
Disclosure Date: April 03, 2020 (last updated February 21, 2025)
A SQL injection vulnerability in TestLink 1.9.20 allows attackers to execute arbitrary SQL commands in dragdroptreenodes.php via the node_id parameter.
0
Attacker Value
Unknown
CVE-2020-8639
Disclosure Date: April 03, 2020 (last updated February 21, 2025)
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute arbitrary code by uploading a file with an executable extension. This allows an authenticated attacker to upload a malicious file (containing PHP code to execute operating system commands) to a publicly accessible directory of the application.
0