CVE-2008-5807: XSS
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) Testproject Names and (2) Testplan Names in planEdit.php, and possibly (3) Testcaseprefixes in projectview.tpl.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TestLinkto a version that resolves this vulnerability.Fixed in 1.8 RC1
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5807?
CVE-2008-5807 is classified as a high severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2008-5807?
To fix CVE-2008-5807, upgrade to TestLink version 1.8 RC1 or later, which addresses these vulnerabilities.
What types of attacks does CVE-2008-5807 facilitate?
CVE-2008-5807 facilitates cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary web scripts or HTML.
Which versions of TestLink are affected by CVE-2008-5807?
CVE-2008-5807 affects TestLink versions up to 1.8 and specific earlier versions including 1.7.1 to 1.7.4 and 1.8 beta releases.
Can CVE-2008-5807 be exploited remotely?
Yes, CVE-2008-5807 can be exploited remotely by attackers through crafted project or test plan names.