Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2009-3255 (rash)

BugsAlert Home > CVE-2009-3255 (rash)
 
 

SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.




Original Source: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3255

Learn more about CVE-2009-3255 (rash)
 
Tags: cve-2009-3255 rash

Related Items

      Documentation Problem 51318 [Open] de/pl translation mysql_fetch_object() - missing arguments

      VUPEN - Drupal UTF-7 Sequences Handling Cross Site Scripting Vulnerability

      David Mandelin: PLDI 2009

      ReflectionClass::newInstanceArgs cannot instantiate a constructorless class

      Adalat Buy Adalat online No prescription SALE

      openSUSE libxcrypt MD5 Password Hash Configuration Weakness

      Security Updates for Adobe Reader and Acrobat

 

Pixel