E18-0oqy1
CVSS:
6.0 (AV:N/AC:M/Au:S/C:P/I:P/A:P)
False Positive:
t
Variants:
1
Year:
2018
Description
This strike exploits a code injection vulnerability in TestLink Open Source Test Management. The vulnerability is due to improper sanitization and handling of user-controlled values passed for TestLink DB login parameter in installNewDB.php script. By exploiting this vulnerability, a remote, unauthenticated attacker can inject and execute arbitrary PHP code on the target server. NOTE: When run in one-arm mode, a Mysql server must be accessible at localhost and user root with password 12345 must be configured. Also a database called testlink must be created and Mysql must be configured to accept usernames longer that 16 characters.
CVE
References
MSB
BID
ExploitDB
Secunia
Security Tracker
Metasploit
ZDI
OSVDB
{}