TestLink SQL Injection Vulnerability Fixed by 1.9.15
Description
(#A SQL injection vulnerability has been identified in TestLink.#A remote attacker could exploit it by sending crafted URLs that include SQL statements in order to modify or delete entries in some database tables.##This vulnerability is due to a lack of user input check.#Updated, 17/02/2016:#A proof of concept is available.)