CVE-2008-4620

EUVD-2008-4600
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
mrbsmrbs
𝑥
≤ 1.2.6
mrbsmrbs
0.5
mrbsmrbs
0.6
mrbsmrbs
0.7
mrbsmrbs
0.8
mrbsmrbs
0.8:pre1
mrbsmrbs
0.8:pre2
mrbsmrbs
0.8:pre3
mrbsmrbs
0.8:pre4
mrbsmrbs
0.8:pre5
mrbsmrbs
0.8:pre6
mrbsmrbs
0.9:pre-1
mrbsmrbs
0.9:pre-2
mrbsmrbs
0.9.1
mrbsmrbs
0.9.2
mrbsmrbs
1.0
mrbsmrbs
1.0:pre-1
mrbsmrbs
1.0:pre-2
mrbsmrbs
1.1
mrbsmrbs
1.1:pre-1
mrbsmrbs
1.1:pre-2
mrbsmrbs
1.2
mrbsmrbs
1.2:pre-1
mrbsmrbs
1.2:pre-2
mrbsmrbs
1.2:pre-3
mrbsmrbs
1.2.1
mrbsmrbs
1.2.2
mrbsmrbs
1.2.3
mrbsmrbs
1.2.4
mrbsmrbs
1.2.5
mrbsmrbs
1.2.6.1
𝑥
= Vulnerable software versions