Sårbarhed Detalje Syn
Legend :
critical
high
medium
low
other
| id | 43101 |
| Risiko | other |
| Familie | CGI abuses : XSS |
| Kategori | attack |
| Navn | TestLink login.php req Parameter XSS |
| Sammenfatning | Checks for an XSS issue in TestLink |
| Beskrivelse | Synopsis :
The remote web server is hosting a PHP application that is affected
by a cross-site scripting vulnerability.
Description :
The remote web server is hosting TestLink, a test-management
application written in PHP.
The installed version of TestLink is affected by a cross-site
scripting vulnerability in the 'req' parameter of the 'login.php'
script. An attacker could exploit this flaw to execute arbitrary
script code in a user's browser.
Note that this version is potentially affected by multiple other
issues, though Nessus has not tested for these.
See also :
http://www.nessus.org/u?b28f9d8c
http://www.nessus.org/u?851b4c6f
Solution :
Upgrade to TestLink version 1.8.5 or later.
Risk factor :
Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
|
| CVE |
CVE-2009-4237 |
| Bugtraq |
37258 |
| Copyright |
(C) 2009 Tenable Network Security, Inc. |
|
|