CVE-2018-7466: Code Injection
Published Feb 25, 2018
·Updated
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.
Affected Software
1 affected component
TestLink TestLink<=1.9.16
Event History
Feb 25, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-7466?
CVE-2018-7466 is classified as a medium severity vulnerability due to its potential for remote injection attacks.
2
How do I fix CVE-2018-7466?
To fix CVE-2018-7466, upgrade to TestLink version 1.9.17 or later, which addresses this vulnerability.
3
What types of attacks can be conducted using CVE-2018-7466?
CVE-2018-7466 allows remote attackers to conduct injection attacks by manipulating crafted DB LOGIN NAMES during installation.
4
Which versions of TestLink are affected by CVE-2018-7466?
CVE-2018-7466 affects TestLink versions up to and including 1.9.16.
5
Can CVE-2018-7466 be exploited without authentication?
Yes, CVE-2018-7466 can be exploited by unauthenticated attackers during the installation process.