VendorsAeriesaeries_student_information_system3.8.2.8
Vulnerabilities

Aeries Aeries Student Information System 3.8.2.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2008-0943
Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.
Published 2008-02-25 · Modified
7.53 PoCEPSS 0.010
CVE-2008-0942
SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter.
Published 2008-02-25 · Modified
7.51 PoCEPSS 0.010
CVE-2008-0941
Cross-site scripting (XSS) vulnerability in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to inject arbitrary web script or HTML via an event.
Published 2008-02-25 · Modified
4.3EPSS 0.011