{ "id": "CVE-2009-3533", "sourceIdentifier": "cve@mitre.org", "published": "2009-10-02T19:30:00.377", "lastModified": "2024-11-21T01:07:35.823", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information." }, { "lang": "es", "value": "Vulnerabilidad de inyecci\u00f3n SQL en report.php en Meeting Room Booking System (MRBS) anterior v1.4.2 permite a atacantes remotos ejecutar comandos SQL de su elecci\u00f3n a trav\u00e9s del par\u00e1metro typematch. NOTA: algunos de estos detalles han sido obtenidos a partir de informaci\u00f3n de terceros." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "baseScore": 7.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL" }, "baseSeverity": "HIGH", "exploitabilityScore": 10.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-89" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:*:*:*:*:*:*:*:*", "versionEndIncluding": "1.4.1", "matchCriteriaId": "5DC04A18-963C-43D0-9E21-73FFE4856193" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.1:*:*:*:*:*:*:*", "matchCriteriaId": "421AD89F-3ED6-4FFD-9742-FBF0FCAD42DB" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.2:*:*:*:*:*:*:*", "matchCriteriaId": "F980185B-D9DB-4B19-BCDC-9ECC8FA63D86" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.5:*:*:*:*:*:*:*", "matchCriteriaId": "0A6D7CF5-DF60-41A6-BE41-B757051FD6AF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.6:*:*:*:*:*:*:*", "matchCriteriaId": "8A3EDDCF-F6CD-41CB-8129-BAF968537D5E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.7:*:*:*:*:*:*:*", "matchCriteriaId": "AFCD0C65-5C18-400C-BF7C-AF3ABE1168CC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8:*:*:*:*:*:*:*", "matchCriteriaId": "C9986257-5953-4768-803B-8BF70E6E7523" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8-pre1:*:*:*:*:*:*:*", "matchCriteriaId": "5020393F-EED7-4DDC-9193-BB68232C8606" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8-pre2:*:*:*:*:*:*:*", "matchCriteriaId": "6841D1CE-1BF5-48C0-96DD-83BCB9AFB2FF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8-pre3:*:*:*:*:*:*:*", "matchCriteriaId": "F04E6381-CEC9-416B-AD08-A9D7B7C62D08" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8-pre4:*:*:*:*:*:*:*", "matchCriteriaId": "6CF34656-302A-49F0-B86E-0D504DA921CD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8-pre5:*:*:*:*:*:*:*", "matchCriteriaId": "F4C7905A-12A1-4E3F-AEC9-21E993C54D42" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8-pre6:*:*:*:*:*:*:*", "matchCriteriaId": "F238F274-B07F-4F1F-A890-B52CACB78278" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.8.1:*:*:*:*:*:*:*", "matchCriteriaId": "6159F627-20A1-4DFF-AD5C-79436FB20573" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.9:*:*:*:*:*:*:*", "matchCriteriaId": "9DFCA2FA-6E92-4FD0-BA51-B77E6DB16557" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.9-pre1:*:*:*:*:*:*:*", "matchCriteriaId": "4C76758C-E8BD-464F-855D-F2769B67E679" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.9-pre2:*:*:*:*:*:*:*", "matchCriteriaId": "EE233B81-62D6-4EEF-9FDE-832407138E34" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.9.1:*:*:*:*:*:*:*", "matchCriteriaId": "7DE4F300-10ED-4201-922E-E568D0159225" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:0.9.2:*:*:*:*:*:*:*", "matchCriteriaId": "209C7517-46A1-4EC7-8081-D05CE2A9E756" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.0:*:*:*:*:*:*:*", "matchCriteriaId": "04FDDA28-E37C-4CB0-BE8D-29DD336D7D0C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.0-pre1:*:*:*:*:*:*:*", "matchCriteriaId": "95C2ACC0-7D3B-4A27-870C-0AEB288C27C1" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.0-pre2:*:*:*:*:*:*:*", "matchCriteriaId": "F580F4F9-E70F-4CDA-92C7-1D9F68CC4165" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.1:*:*:*:*:*:*:*", "matchCriteriaId": "27B8F4B5-6D12-43C4-B31C-81F2C59470F6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.1-pre1:*:*:*:*:*:*:*", "matchCriteriaId": "C0CDDF03-F2BD-4C33-BBFC-4CB10E4FA164" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.1-pre2:*:*:*:*:*:*:*", "matchCriteriaId": "30FB9DA5-83FB-489B-AF38-86A12871083F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2:*:*:*:*:*:*:*", "matchCriteriaId": "ADB34BB1-20AD-49EF-BB47-8C359B157EA6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2-pre3:*:*:*:*:*:*:*", "matchCriteriaId": "BC178F37-45DC-4F4E-9D5B-6E96D2A73A92" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "73AF4C98-744A-4556-AB2A-BE240765E04C" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.1-pre1:*:*:*:*:*:*:*", "matchCriteriaId": "8DA7DBEC-2CFD-410D-8768-D0BA06D845B4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.1-pre2:*:*:*:*:*:*:*", "matchCriteriaId": "AA799F6C-10BF-43BF-A30B-0817C92F8B69" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.2:*:*:*:*:*:*:*", "matchCriteriaId": "07387023-C4AE-46B1-A452-B283AE5DF483" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.3:*:*:*:*:*:*:*", "matchCriteriaId": "7B42C795-0A62-4FCB-B032-61A30AF5FA78" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.4:*:*:*:*:*:*:*", "matchCriteriaId": "B25C8DAD-74AA-49C3-B813-E6A3D38AC69F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.5:*:*:*:*:*:*:*", "matchCriteriaId": "29EDE276-EC6D-4B95-8C96-CBC1C86E2E59" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.6:*:*:*:*:*:*:*", "matchCriteriaId": "3A88A9E7-8BF5-4934-A26C-3D2CE5DC6104" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.2.6.1:*:*:*:*:*:*:*", "matchCriteriaId": "5214C975-36A2-426D-848C-9B9338FC2AFF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:john_beranek:meeting_room_booking_system:1.4:*:*:*:*:*:*:*", "matchCriteriaId": "30106CC6-D301-4305-A290-E7E190A3FED7" } ] } ] } ], "references": [ { "url": "http://mrbs.sourceforge.net/view_text.php?section=NEWS&file=NEWS", "source": "cve@mitre.org" }, { "url": "http://osvdb.org/55872", "source": "cve@mitre.org" }, { "url": "http://secunia.com/advisories/35469", "source": "cve@mitre.org", "tags": [ "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51772", "source": "cve@mitre.org" }, { "url": "http://mrbs.sourceforge.net/view_text.php?section=NEWS&file=NEWS", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://osvdb.org/55872", "source": "af854a3a-2127-422b-91ae-364da2661108" }, { "url": "http://secunia.com/advisories/35469", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51772", "source": "af854a3a-2127-422b-91ae-364da2661108" } ] }