CVE-2009-3255
18.09.2009, 20:30
SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.
Vendor | Product | Version |
---|---|---|
thomas_cuchta | rash | 𝑥 ≤ 1.2.2 |
thomas_cuchta | rash | 1.0 |
thomas_cuchta | rash | 1.1 |
thomas_cuchta | rash | 1.1.1 |
thomas_cuchta | rash | 1.1.2 |
thomas_cuchta | rash | 1.1.3 |
thomas_cuchta | rash | 1.2 |
thomas_cuchta | rash | 1.2.1 |
𝑥
= Vulnerable software versions
References