vendor:
Meeting Room Booking System
by:
Xianur0
8.8
CVSS
HIGH
Blind SQL Injection
89
CWE
Product Name: Meeting Room Booking System
Affected Version From: Previous versions of mrbs 1.4
Affected Version To: Previous versions of mrbs 1.4
Patch Exists: YES
Related CWE: N/A
CPE: a:mrbs:mrbs
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
MRBS Blind SQL Injection Vulnerability
A Blind SQL Injection vulnerability was discovered in the Meeting Room Booking System (MRBS) which allows an attacker to inject malicious SQL queries into the application. The vulnerability exists in the ‘month.php’, ‘day.php’ and ‘week.php’ scripts, which are vulnerable to a Blind SQL Injection attack. An attacker can exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable scripts with a malicious SQL query. This can allow the attacker to gain access to sensitive information from the database.
Mitigation:
Update to the latest version of MRBS (1.4) to patch the vulnerability.