TestLink 'debug_print_backtrace()' Function Information Disclosure Weakness
BID:70713
Info
TestLink 'debug_print_backtrace()' Function Information Disclosure Weakness
| Bugtraq ID: | 70713 |
| Class: | Design Error |
| CVE: |
CVE-2014-8082 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2014 12:00AM |
| Updated: | Oct 23 2014 12:00AM |
| Credit: | Egidio Romano |
| Vulnerable: |
TestLink TestLink 1.9.12 TestLink TestLink 1.9.11 TestLink TestLink 1.9.3 TestLink TestLink 1.8.5 TestLink TestLink 1.8.4 TestLink TestLink 1.8.3 TestLink TestLink 1.8.2 TestLink TestLink 1.8.1 TestLink TestLink 1.8 TestLink TestLink 1.7.4 TestLink TestLink 1.7.1 TestLink TestLink 1.7 TestLink TestLink 1.8.5b TestLink TestLink 1.8 RC1 |
| Not Vulnerable: |
TestLink TestLink 1.9.13 |
Exploit / POC
TestLink 'debug_print_backtrace()' Function Information Disclosure Weakness
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
TestLink 'debug_print_backtrace()' Function Information Disclosure Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
TestLink 'debug_print_backtrace()' Function Information Disclosure Weakness
References:
References:
- TestLink - Homepage (TestLink)
- TestLink - PHP Object Injection Vulnerability In /lib/execute/execSetResults.php (Egidio Romano)
- TestLink <= 1.9.12 (database.class.php) Path Disclosure Weakness (Egidio Romano)