Meeting Room Booking System 'typematch' Parameter SQL Injection Vulnerability
BID:43550
Info
Meeting Room Booking System 'typematch' Parameter SQL Injection Vulnerability
| Bugtraq ID: | 43550 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3533 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2009 12:00AM |
| Updated: | Jul 16 2009 12:00AM |
| Credit: | Stefano Angaran |
| Vulnerable: |
Meeting Room Booking Software MRBS 1.4.1 |
| Not Vulnerable: |
Meeting Room Booking Software MRBS 1.4.2 |
Discussion
Meeting Room Booking System 'typematch' Parameter SQL Injection Vulnerability
Meeting Room Booking System is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Meeting Room Booking System 1.4.1 is vulnerable; other versions may also be affected.
Meeting Room Booking System is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Meeting Room Booking System 1.4.1 is vulnerable; other versions may also be affected.
Exploit / POC
Meeting Room Booking System 'typematch' Parameter SQL Injection Vulnerability
An attacker can exploit this issue with a browser.
An attacker can exploit this issue with a browser.
Solution / Fix
Meeting Room Booking System 'typematch' Parameter SQL Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.