Vulnerabilities > Thomas Cuchta

DATE CVE VULNERABILITY TITLE RISK
2009-09-18 CVE-2009-3259 SQL Injection vulnerability in Thomas Cuchta Rash 1.2.2
Multiple SQL injection vulnerabilities in RASH Quote Management System (RQMS) 1.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the search parameter in a search action, (2) the quote parameter in a quote addition, or (3) a User_Name cookie in unspecified administrative actions.
network
low complexity
thomas-cuchta CWE-89
7.5
2009-09-18 CVE-2009-3255 SQL Injection vulnerability in Thomas Cuchta Rash
SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.
6.8