{"api_version":"1","generated_at":"2026-07-23T11:09:51+00:00","cve":"CVE-2008-0943","urls":{"html":"https://cve.report/CVE-2008-0943","api":"https://cve.report/api/cve/CVE-2008-0943.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-0943","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-0943"},"summary":{"title":"CVE-2008-0943","description":"Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-02-25 21:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/488428/100/0/threaded","name":"http://www.securityfocus.com/archive/1/488428/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40757","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/27924","name":"http://www.securityfocus.com/bid/27924","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Aeries Student Information System Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/29053","name":"http://secunia.com/advisories/29053","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Aeries Browser Interface Script Insertion and SQL Injection - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3696","name":"http://securityreason.com/securityalert/3696","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - aeries browser interface(ABI) 3.7.2.2 Remote SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-0943","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-0943","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"943","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aeries","cpe5":"aeries_student_information_system","cpe6":"3.7.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"943","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"aeries","cpe5":"aeries_student_information_system","cpe6":"3.8.2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:01:40.088Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20080221 aeries browser interface(ABI) 3.7.2.2 Remote SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/488428/100/0/threaded"},{"name":"29053","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29053"},{"name":"27924","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27924"},{"name":"3696","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3696"},{"name":"abi-fcterm-sql-injection(40757)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40757"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-02-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20080221 aeries browser interface(ABI) 3.7.2.2 Remote SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/488428/100/0/threaded"},{"name":"29053","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29053"},{"name":"27924","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27924"},{"name":"3696","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3696"},{"name":"abi-fcterm-sql-injection(40757)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40757"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-0943","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20080221 aeries browser interface(ABI) 3.7.2.2 Remote SQL Injection","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/488428/100/0/threaded"},{"name":"29053","refsource":"SECUNIA","url":"http://secunia.com/advisories/29053"},{"name":"27924","refsource":"BID","url":"http://www.securityfocus.com/bid/27924"},{"name":"3696","refsource":"SREASON","url":"http://securityreason.com/securityalert/3696"},{"name":"abi-fcterm-sql-injection(40757)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/40757"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-0943","datePublished":"2008-02-25T21:00:00.000Z","dateReserved":"2008-02-25T00:00:00.000Z","dateUpdated":"2024-08-07T08:01:40.088Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-02-25 21:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:aeries:aeries_student_information_system:3.7.2.2:*:*:*:*:*:*:*","matchCriteriaId":"982E379E-6784-4914-9B39-7398BD46F051"},{"vulnerable":true,"criteria":"cpe:2.3:a:aeries:aeries_student_information_system:3.8.2.8:*:*:*:*:*:*:*","matchCriteriaId":"67AEF538-9296-498D-AC7C-869C65D6F91C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"943","Ordinal":"1","Title":"CVE-2008-0943","CVE":"CVE-2008-0943","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"943","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.","Type":"Description","Title":"CVE-2008-0943"},{"CveYear":"2008","CveId":"943","Ordinal":"2","NoteData":"2008-02-25","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"943","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}