CVE-2014-5308: SQL Injection
Published Oct 8, 2014
·Updated
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.
Affected Software
1 affected component
TestLink TestLink=1.9.11
Event History
Oct 8, 2014
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5308?
CVE-2014-5308 is classified as a medium severity vulnerability.
2
How can I mitigate CVE-2014-5308?
To mitigate CVE-2014-5308, you should upgrade TestLink to the latest version that addresses these SQL injection vulnerabilities.
3
Who is affected by CVE-2014-5308?
CVE-2014-5308 affects authenticated users of TestLink version 1.9.11.
4
What types of attacks can be executed due to CVE-2014-5308?
Due to CVE-2014-5308, an attacker can execute arbitrary SQL commands within the affected TestLink application.
5
Can CVE-2014-5308 be exploited remotely?
Yes, CVE-2014-5308 can be exploited by remote authenticated users.