4450Third-party advisory
http://securityreason.com/securityalert/4450 CVE-2008-4620
Meeting Room Booking System (MRBS) < 1.4 - SQL Injection
Record summary
CVE-2008-4620 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMeeting Room Booking System (MRBS) < 1.4 - SQL InjectionExploitDB exploitby Xianur0Not analyzed1 file
References
631809vdb entry
http://www.securityfocus.com/bid/31809 ADV-2008-2865vdb entry
http://www.vupen.com/english/advisories/2008/2865 mrbs-area-sql-injection(45972)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45972 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-4620 6781exploit
https://www.exploit-db.com/exploits/6781