CVE-2008-1549 Information
Feb 14, 2021
cve
Description
Multiple SQL injection vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to execute arbitrary SQL commands via the (1) GrdBk parameter to GradebookOptions.asp and the (2) SchlCode variable to loginproc.asp a different vector than CVE-2008-0942.
Reference
http://secunia.com/advisories/29533 http://securityreason.com/securityalert/3787 http://www.securityfocus.com/archive/1/490033/100/0/threaded http://www.securityfocus.com/bid/28436 https://exchange.xforce.ibmcloud.com/vulnerabilities/41429
Share on: