Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-20107

EPSS 1.78% · P83
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-20107

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple SQL injection vulnerabilities in TestLink through 1.9.19 allows remote authenticated users to execute arbitrary SQL commands via the (1) tproject_id parameter to keywordsView.php; the (2) req_spec_id parameter to reqSpecCompareRevisions.php; the (3) requirement_id parameter to reqCompareVersions.php; the (4) build_id parameter to planUpdateTC.php; the (5) tplan_id parameter to newest_tcversions.php; the (6) tplan_id parameter to tcCreatedPerUserGUI.php; the (7) tcase_id parameter to tcAssign2Tplan.php; or the (8) testcase_id parameter to tcCompareVersions.php. Authentication is often easy to achieve: a guest account, that can execute this attack, can be created by anyone in the default configuration.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
TestLink SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TestLink是一套用于管理软件测试过程并提供统计分析的开源软件。 TestLink 1.9.19及之前版本中存在SQL注入漏洞。远程攻击者可借助‘tproject_id’等参数利用该漏洞执行任意SQL命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-20107

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-20107

登录查看更多情报信息。

Same Patch Batch · n/a · 2020-03-05 · 35 CVEs total

CVE-2020-10098Zammad 跨站脚本漏洞
CVE-2020-10173Comtrend VR-3033 操作系统命令注入漏洞
CVE-2019-20501D-Link DWL-2600AP 操作系统命令注入漏洞
CVE-2020-9380IPTV Smarters WEB TV PLAYER 代码问题漏洞
CVE-2020-10107PHPGurukul Daily Expense Tracker System 跨站脚本漏洞
CVE-2020-10106PHPGurukul Daily Expense Tracker System SQL注入漏洞
CVE-2020-9370HUMAX HGA12R-02 BRGCAA 授权问题漏洞
CVE-2020-10096Zammad 信息泄露漏洞
CVE-2020-10097Zammad 安全漏洞
CVE-2019-20500D-Link DWL-2600AP 操作系统命令注入漏洞
CVE-2020-10099Zammad 跨站脚本漏洞
CVE-2020-10100Zammad 信息泄露漏洞
CVE-2020-10101Zammad 输入验证错误漏洞
CVE-2020-10102Zammad 安全漏洞
CVE-2020-10103Zammad 跨站脚本漏洞
CVE-2020-10104Zammad 信息泄露漏洞
CVE-2020-10105Zammad 信息泄露漏洞
CVE-2019-17642Centreon 跨站请求伪造漏洞
CVE-2020-10185Yubico YubiKey Validation Server 安全漏洞
CVE-2020-6986Omron PLC CJ series 资源管理错误漏洞

Showing top 20 of 35 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-20107

No comments yet


Leave a comment