CVE-2008-4620

SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
mrbsmrbs
𝑥
≤ 1.2.6
mrbsmrbs
0.5
mrbsmrbs
0.6
mrbsmrbs
0.7
mrbsmrbs
0.8
mrbsmrbs
0.8:pre1
mrbsmrbs
0.8:pre2
mrbsmrbs
0.8:pre3
mrbsmrbs
0.8:pre4
mrbsmrbs
0.8:pre5
mrbsmrbs
0.8:pre6
mrbsmrbs
0.9:pre-1
mrbsmrbs
0.9:pre-2
mrbsmrbs
0.9.1
mrbsmrbs
0.9.2
mrbsmrbs
1.0
mrbsmrbs
1.0:pre-1
mrbsmrbs
1.0:pre-2
mrbsmrbs
1.1
mrbsmrbs
1.1:pre-1
mrbsmrbs
1.1:pre-2
mrbsmrbs
1.2
mrbsmrbs
1.2:pre-1
mrbsmrbs
1.2:pre-2
mrbsmrbs
1.2:pre-3
mrbsmrbs
1.2.1
mrbsmrbs
1.2.2
mrbsmrbs
1.2.3
mrbsmrbs
1.2.4
mrbsmrbs
1.2.5
mrbsmrbs
1.2.6.1
𝑥
= Vulnerable software versions