7.5
CVSSv2

CVE-2008-4620

Published: 21/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in Meeting Room Booking System (MRBS) prior to 1.4 allows remote malicious users to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.

Vulnerable Product Search on Vulmon Subscribe to Product

mrbs mrbs 1.2.3

mrbs mrbs 1.2.2

mrbs mrbs 1.2.1

mrbs mrbs 1.1

mrbs mrbs 1.0

mrbs mrbs 0.8

mrbs mrbs 0.5

mrbs mrbs 1.2.5

mrbs mrbs 1.2.4

mrbs mrbs 0.9

mrbs mrbs 0.7

mrbs mrbs 0.6

mrbs mrbs

mrbs mrbs 1.2.6.1

mrbs mrbs 1.2

mrbs mrbs 0.9.2

mrbs mrbs 0.9.1

Exploits

# "MRBS is a system for multi-site booking of meeting rooms Rooms are grouped by building/area and shown in a side-by-side view Although the goal was initially to book rooms, MRBS can also be used to book any resource (computer, planes, whatever you want)" # Web CMS: sourceforgenet/projects/mrbs/ # Affected: Previous versions of mrbs 1 ...