CVE-2012-0938: SQL Injection
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the rootnode parameter in the displaychildren function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfieldid parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) planid parameter in a create action to lib/plan/planMilestonesEdit.php; or the reqspecid parameter to (6) reqImport.php or (7) in a create action to reqEdit.php in lib/requirements/. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0938?
CVE-2012-0938 is classified as a medium to high severity vulnerability due to its potential to allow unauthorized SQL command execution.
How do I fix CVE-2012-0938?
To fix CVE-2012-0938, update TestLink to the latest version that mitigates these SQL injection vulnerabilities.
What are the affected versions for CVE-2012-0938?
CVE-2012-0938 affects TestLink versions 1.9.3, 1.8.5b, and earlier.
Who can exploit CVE-2012-0938?
CVE-2012-0938 can be exploited by remote authenticated users with specific permissions.
What is the impact of exploiting CVE-2012-0938?
Exploiting CVE-2012-0938 can allow attackers to execute arbitrary SQL commands, leading to potential data exposure or manipulation.