mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-15 07:40:25 +02:00
785 B
785 B
CVE-2009-3255
Description
SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.
POC
Reference
- http://packetstormsecurity.org/0908-exploits/rqms-bypass.txt
- http://packetstormsecurity.org/0908-exploits/rqms-bypass.txt
Github
No PoCs found on GitHub currently.