40690 |
CVE-2009-3255 |
Candidate |
SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI. |
Assigned (20090918) |
None (candidate not yet proposed) |
|
View
|
40946 |
CVE-2009-3511 |
Candidate |
Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php. |
Assigned (20091001) |
None (candidate not yet proposed) |
|
View
|
41202 |
CVE-2009-3767 |
Candidate |
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a " |