eSikker.dk

Sårbarhed Detalje Syn
Legend : critical high medium low other
id 43101
Risiko other
Familie CGI abuses : XSS
Kategori attack
Navn TestLink login.php req Parameter XSS
Sammenfatning Checks for an XSS issue in TestLink
Beskrivelse Synopsis :

The remote web server is hosting a PHP application that is affected
by a cross-site scripting vulnerability.

Description :

The remote web server is hosting TestLink, a test-management
application written in PHP.

The installed version of TestLink is affected by a cross-site
scripting vulnerability in the 'req' parameter of the 'login.php'
script. An attacker could exploit this flaw to execute arbitrary
script code in a user's browser.

Note that this version is potentially affected by multiple other
issues, though Nessus has not tested for these.

See also :

http://www.nessus.org/u?b28f9d8c
http://www.nessus.org/u?851b4c6f

Solution :

Upgrade to TestLink version 1.8.5 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVE CVE-2009-4237
Bugtraq 37258
Copyright (C) 2009 Tenable Network Security, Inc.
103
PCbix kan findes hos twitter PC håndværkeren - Er din PC i stykker? Banken lukkede din netbank? Har din PC virus? Ekstern USB harddisk kasse med eller uden harddisk. Lillekilde i Valby Studiehuset Ole Opfinder Hosted by FLIFL
design by Pingvino