aeries browser interface(ABI) 3.8.3.14 Remote SQL Injection

2008.03.31
Credit: arsalan1991
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-89

Discovered By : Arsalan Emamjomehkashan aeries browser interface(ABI) 3.8.3.14 Remote SQL Injection Website:http://aeries.com/ SQL injection: GradebookOptions.asp?GrdBk=SQL loginproc.asp If you post variable "SchlCode" XSS: UserName variable on loginproc.asp and usr on Login.asp


Vote for this issue:
50%
50%

Comment it here.

Copyright 2025, cxsecurity.com

 

Back to Top