CVE-2009-4238: SQL Injection
Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/navBar.php or (2) the logLevel parameter to lib/events/eventviewer.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4238?
CVE-2009-4238 has a medium severity rating as it allows remote authenticated users to execute arbitrary SQL commands.
How do I fix CVE-2009-4238?
To fix CVE-2009-4238, you should upgrade TestLink to version 1.8.5 or later, which addresses these SQL injection vulnerabilities.
What versions of TestLink are affected by CVE-2009-4238?
CVE-2009-4238 affects TestLink versions 1.7, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.8, and its beta and release candidates before 1.8.5.
Can I exploit CVE-2009-4238 without valid credentials?
No, CVE-2009-4238 requires valid authenticated user credentials to exploit the SQL injection vulnerabilities.
What are the potential impacts of CVE-2009-4238 on my TestLink installation?
Exploiting CVE-2009-4238 may lead to unauthorized access to the database, allowing attackers to manipulate or extract sensitive information.