CVE-2007-6538

MRBS - SQL Injection via id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6538. PoCs published by [email protected].

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in MRBS (Meeting Room Booking System) by injecting a UNION SELECT query to retrieve user data from the database. The vulnerability arises from insufficient sanitization of the 'id' parameter in the 'view_entry.php' script.

Description

SQL injection vulnerability in ing/blocks/mrbs/code/web/view_entry.php in the MRBS plugin for Moodle allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by [email protected] · textwebappsphp
https://www.exploit-db.com/exploits/30921

This exploit demonstrates an SQL injection vulnerability in MRBS (Meeting Room Booking System) by injecting a UNION SELECT query to retrieve user data from the database. The vulnerability arises from insufficient sanitization of the 'id' parameter in the 'view_entry.php' script.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: MRBS (Meeting Room Booking System) and MRBS module for Moodle
No auth needed
Prerequisites: Access to the vulnerable MRBS or Moodle MRBS module web interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28198
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485459/100/200/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485455/100/200/threaded
Exploit third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3492
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/39619
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39190
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/485434/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26977

Scores

EPSS 0.0163
EPSS Percentile 82.1%

Details

CWE
CWE-89
Status published
Products (2)
mrbs/mrbs 1.2.3
mrbs/mrbs 1.2.5
Published Dec 27, 2007
Tracked Since Feb 18, 2026