CVE-2008-4620: SQL Injection
SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4620?
CVE-2008-4620 is considered a high severity SQL injection vulnerability due to the potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2008-4620?
To fix CVE-2008-4620, upgrade to Meeting Room Booking System (MRBS) version 1.4 or later, where the vulnerability is addressed.
Which versions of MRBS are affected by CVE-2008-4620?
CVE-2008-4620 affects MRBS versions prior to 1.4, including all pre-release versions and versions up to 1.2.6.
What impact does CVE-2008-4620 have on the system?
The impact of CVE-2008-4620 allows attackers to manipulate database queries, potentially leading to unauthorized data access or modification.
Is my MRBS installation vulnerable to CVE-2008-4620?
If you are running an MRBS version prior to 1.4, your installation is vulnerable to CVE-2008-4620 and should be updated immediately.