TestLink Multiple HTML Injection Vulnerabilities
BID:32173
Info
TestLink Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 32173 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5807 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | TestLink |
| Vulnerable: |
TestLink TestLink 1.7.4 TestLink TestLink 1.7.1 TestLink TestLink 1.7 TestLink TestLink 0 |
| Not Vulnerable: |
TestLink TestLink 1.8 RC1 |
Discussion
TestLink Multiple HTML Injection Vulnerabilities
TestLink is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to TestLink 1.8 RC1 are vulnerable.
TestLink is prone to multiple HTML-injection vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML and script code would execute in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks are also possible.
Versions prior to TestLink 1.8 RC1 are vulnerable.
Exploit / POC
TestLink Multiple HTML Injection Vulnerabilities
Attackers can exploit these issues using a browser.
Attackers can exploit these issues using a browser.
Solution / Fix
TestLink Multiple HTML Injection Vulnerabilities
Solution:
These issues have been addressed in TestLink 1.8 RC1. Please see the references for more information.
Solution:
These issues have been addressed in TestLink 1.8 RC1. Please see the references for more information.
References
TestLink Multiple HTML Injection Vulnerabilities
References:
References:
- Release Name: TestLink 1.8 RC1 (TestLink)
- TestLink Homepage (TestLink)