CVE-2014-8081: Code Injection
Published Oct 31, 2014
·Updated
lib/execute/execSetResults.php in TestLink before 1.9.13 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the filterresultresult parameter.
Affected Software
1 affected component
TestLink TestLink<=1.9.12
Remediation
Patch Available
Patch Available
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8081?
CVE-2014-8081 is considered critical due to the potential for remote code execution through PHP object injection.
2
How do I fix CVE-2014-8081?
To fix CVE-2014-8081, upgrade TestLink to version 1.9.13 or later.
3
What type of attack does CVE-2014-8081 facilitate?
CVE-2014-8081 facilitates PHP object injection attacks allowing arbitrary code execution.
4
Which versions of TestLink are affected by CVE-2014-8081?
TestLink versions prior to 1.9.13 are affected by CVE-2014-8081.
5
How does CVE-2014-8081 impact web application security?
CVE-2014-8081 impacts web application security by enabling remote attackers to execute arbitrary PHP code on vulnerable systems.