TestLink Multiple Security Vulnerabilities
BID:54990
Info
TestLink Multiple Security Vulnerabilities
| Bugtraq ID: | 54990 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2012 12:00AM |
| Updated: | Aug 13 2012 12:00AM |
| Credit: | Brendan Coles |
| Vulnerable: |
TestLink TestLink 1.9.3 |
| Not Vulnerable: | |
Discussion
TestLink Multiple Security Vulnerabilities
TestLink is prone to multiple security vulnerabilities, including:
1. An arbitrary file-upload vulnerability
2. An information-disclosure vulnerability
3. A cross-site request-forgery vulnerability
Exploiting these vulnerabilities may allow an attacker to harvest sensitive information, upload and execute arbitrary server side code in the context of the web server, or perform unauthorized actions on behalf of a user in the context of the site. This may aid in launching further attacks.
TestLink is prone to multiple security vulnerabilities, including:
1. An arbitrary file-upload vulnerability
2. An information-disclosure vulnerability
3. A cross-site request-forgery vulnerability
Exploiting these vulnerabilities may allow an attacker to harvest sensitive information, upload and execute arbitrary server side code in the context of the web server, or perform unauthorized actions on behalf of a user in the context of the site. This may aid in launching further attacks.
Exploit / POC
TestLink Multiple Security Vulnerabilities
An attacker can use a web browser to exploit these issues. To exploit a cross-site scripting or cross-site request forgery vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/testlink-1.9.3/lib/usermanagement/usersEdit.php?user_id=&user_login=&login=asdf&firstName=asdf&lastName=asdf&password=asdf&emailAddress=asdf%40localhost.abc&rights_id=8&locale=en_GB&user_is_active=on&doAction=doCreate&do_update=Save
http://www.example.com/testlink-1.9.3/sysinfo.php
The following exploit is available:
An attacker can use a web browser to exploit these issues. To exploit a cross-site scripting or cross-site request forgery vulnerability, an attacker must entice an unsuspecting user to follow a malicious URI.
The following example URIs are available:
http://www.example.com/testlink-1.9.3/lib/usermanagement/usersEdit.php?user_id=&user_login=&login=asdf&firstName=asdf&lastName=asdf&password=asdf&emailAddress=asdf%40localhost.abc&rights_id=8&locale=en_GB&user_is_active=on&doAction=doCreate&do_update=Save
http://www.example.com/testlink-1.9.3/sysinfo.php
The following exploit is available:
Solution / Fix
TestLink Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
TestLink Multiple Security Vulnerabilities
References:
References:
- TestLink 1.9.3 multiple vulnerabilities (Brendan Coles)
- TestLink Homepage (TestLink)