Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-4237 | First vendor Publication | 2009-12-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:S/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 3.5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 6.8 | Authentication | Requires single instance |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the req parameter to login.php, and allow remote authenticated users to inject arbitrary web script or HTML via (2) the key parameter to lib/general/staticPage.php, (3) the tableName parameter to lib/attachments/attachmentupload.php, or the (4) startDate, (5) endDate, or (6) logLevel parameter to lib/events/eventviewer.php; (7) the search_notes_string parameter to lib/results/resultsMoreBuilds_buildReport.php; or the (8) expected_results, (9) name, (10) steps, or (11) summary parameter in a find action to lib/testcases/searchData.php, related to lib/functions/database.class.php. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-79 | Failure to Preserve Web Page Structure ('Cross-site Scripting') (CWE/SANS Top 25) |
CPE : Common Platform Enumeration
ExploitDB Exploits
id | Description |
---|---|
2009-12-09 | Multiple XSS and Injection Vulnerabilities in TestLink Test Management and Ex... |
OpenVAS Exploits
Date | Description |
---|---|
2009-12-10 | Name : TestLink Cross Site Scripting and SQL Injection Vulnerabilities File : nvt/testlink_37258.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
60981 | TestLink lib/testcases/searchData.php Multiple Parameter XSS |
60921 | TestLink lib/testcases/searchData.php summary Parameter XSS |
60918 | TestLink lib/results/resultsMoreBuilds_buildReport.php search_notes_string Pa... |
60917 | TestLink lib/events/eventviewer.php Multiple Parameter XSS |
60916 | TestLink lib/attachments/attachmentupload.php tableName Parameter XSS |
60915 | TestLink lib/general/staticPage.php key Parameter XSS |
60914 | TestLink login.php req Parameter XSS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-12-10 | Name : The remote web server is hosting a PHP application that is affected by a cros... File : testlink_login_req_param_xss.nasl - Type : ACT_ATTACK |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:09:46 |
|
2024-11-28 12:20:22 |
|
2024-02-14 13:28:22 |
|
2021-05-05 01:06:26 |
|
2021-05-04 12:10:34 |
|
2021-04-22 01:11:02 |
|
2020-05-23 01:41:11 |
|
2020-05-23 00:24:41 |
|
2016-06-28 17:55:08 |
|
2016-04-26 19:18:25 |
|
2014-05-05 13:23:05 |
|
2014-02-17 10:52:35 |
|
2013-05-11 00:02:03 |
|