CVE-2008-1548
Multiple cross-site scripting (XSS) vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to inject arbitrary web script or HTML via the (1) UserName parameter to…
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to inject arbitrary web script or HTML via the (1) UserName parameter to loginproc.asp and the (2) usr parameter to Login.asp.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- aeries/aeries student information system
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/29533Vendor Advisory
- http://securityreason.com/securityalert/3787
- http://www.securityfocus.com/archive/1/490033/100/0/threaded
- http://www.securityfocus.com/bid/28436
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41430
- http://secunia.com/advisories/29533Vendor Advisory
- http://securityreason.com/securityalert/3787
- http://www.securityfocus.com/archive/1/490033/100/0/threaded
- http://www.securityfocus.com/bid/28436
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41430
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.