{"id":"CVE-2018-7466","details":"install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging control over DB LOGIN NAMES data during installation to provide a long, crafted value.","modified":"2026-07-08T16:41:32.883148Z","published":"2018-02-25T07:29:00.210Z","references":[{"type":"FIX","url":"https://github.com/TestLinkOpenSourceTRMS/testlink-code/commit/9696012eecbafb0aa21cc346234512c29b474679"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44226/"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/44349/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/testlinkopensourcetrms/testlink-code","events":[{"introduced":"0"},{"last_affected":"7648698b3139f441b18a287239d514bc72996bfe"},{"fixed":"9696012eecbafb0aa21cc346234512c29b474679"}],"database_specific":{"cpe":"cpe:2.3:a:testlink:testlink:*:*:*:*:*:*:.:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.9.16"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.9.16","1.9.15","1.9.4","1.9.14","1.9.13","1.9.12","1.9.11","1.9.10","1.9.9","1.9.8","1.9.7","1.9.6","1.9.5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7466.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}