TestLink Multiple Directory Traversal Vulnerabilities
BID:37824
Info
TestLink Multiple Directory Traversal Vulnerabilities
| Bugtraq ID: | 37824 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2010 12:00AM |
| Updated: | Jan 18 2010 04:31PM |
| Credit: | Prashant Khandelwal |
| Vulnerable: |
TestLink TestLink 1.8.5 TestLink TestLink 1.8.4 TestLink TestLink 1.8.3 TestLink TestLink 1.8.2 TestLink TestLink 1.8.1 TestLink TestLink 1.8 TestLink TestLink 1.7.4 TestLink TestLink 1.7.1 TestLink TestLink 1.7 TestLink TestLink 1.8 RC1 |
| Not Vulnerable: | |
Discussion
TestLink Multiple Directory Traversal Vulnerabilities
TestLink is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to obtain sensitive information that could aid in further attacks.
TestLink 1.8.5 is vulnerable; other versions may also be affected.
TestLink is prone to multiple directory-traversal vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to obtain sensitive information that could aid in further attacks.
TestLink 1.8.5 is vulnerable; other versions may also be affected.
Exploit / POC
TestLink Multiple Directory Traversal Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proofs of concept are available:
Attackers can use a browser to exploit these issues.
The following proofs of concept are available:
Solution / Fix
TestLink Multiple Directory Traversal Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].