This script is Copyright (C) 2009-2011 Tenable Network Security, Inc.
The remote web server is hosting a PHP application that is affected
by a cross-site scripting vulnerability.
The remote web server is hosting TestLink, a test-management
application written in PHP.
The installed version of TestLink is affected by a cross-site
scripting vulnerability in the 'req' parameter of the 'login.php'
script. An attacker could exploit this flaw to execute arbitrary
script code in a user's browser.
Note that this version is potentially affected by multiple other
issues, though Nessus has not tested for these.
See also :
Upgrade to TestLink version 1.8.5 or later.
Risk factor :
Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.6
Public Exploit Available : true