29053Third-party advisory
http://secunia.com/advisories/29053 CVE-2008-0943
Eagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'Comments.asp?FC' SQL Injection
Record summary
CVE-2008-0943 has a selected CVSS score of 7.5; EIP currently links 3 catalogued exploits.
Description
Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBEagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'Comments.asp?FC' SQL InjectionExploitDB exploitby Arsalan EmamjomehkashanNot analyzed1 file
ExploitDBEagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'Labels.asp?Term' SQL InjectionExploitDB exploitby Arsalan EmamjomehkashanNot analyzed1 file
ExploitDBEagle Software Aeries Student Information System 3.7.2.2/3.8.2.8 - 'ClassList.asp?Term' SQL InjectionExploitDB exploitby Arsalan EmamjomehkashanNot analyzed1 file
References
63696Third-party advisory
http://securityreason.com/securityalert/3696 20080221 aeries browser interface(ABI) 3.7.2.2 Remote SQL Injectionmailing list
http://www.securityfocus.com/archive/1/488428/100/0/threaded 27924vdb entry
http://www.securityfocus.com/bid/27924 abi-fcterm-sql-injection(40757)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/40757 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0943