TestLink login.php req Parameter XSS

This script is Copyright (C) 2009-2011 Tenable Network Security, Inc.


Synopsis :

The remote web server is hosting a PHP application that is affected
by a cross-site scripting vulnerability.

Description :

The remote web server is hosting TestLink, a test-management
application written in PHP.

The installed version of TestLink is affected by a cross-site
scripting vulnerability in the 'req' parameter of the 'login.php'
script. An attacker could exploit this flaw to execute arbitrary
script code in a user's browser.

Note that this version is potentially affected by multiple other
issues, though Nessus has not tested for these.

See also :

http://www.nessus.org/u?b28f9d8c
http://www.nessus.org/u?851b4c6f

Solution :

Upgrade to TestLink version 1.8.5 or later.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: CGI abuses : XSS

Nessus Plugin ID: 43101 ()

Bugtraq ID: 37258

CVE ID: CVE-2009-4237