CVE-2012-0939: SQL Injection
Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission to execute arbitrary SQL commands via the reqspecid parameter to (1) reqSpecAnalyse.php, (2) reqSpecPrint.php, or (3) reqSpecView.php in requirements/. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0939?
CVE-2012-0939 is considered to be of medium severity due to its potential to allow unauthorized SQL command execution.
How do I fix CVE-2012-0939?
To fix CVE-2012-0939, upgrade to TestLink version 1.9.4 or later, which resolves the SQL injection vulnerabilities.
Which software versions are affected by CVE-2012-0939?
TestLink versions 1.8.5b and 1.9.3 are affected by CVE-2012-0939.
Who can exploit CVE-2012-0939?
CVE-2012-0939 can be exploited by remote authenticated users with the Requirement view permission.
What are the affected files in CVE-2012-0939?
The affected files in CVE-2012-0939 are reqSpecAnalyse.php, reqSpecPrint.php, and reqSpecView.php.