Required CVE Record Information
Description
SQL injection vulnerability in the forget password section (LostPwd.asp) in Eagle Software Aeries Browser Interface (ABI) 3.7.9.17 allows remote attackers to execute arbitrary SQL commands via the EmailAddress parameter. NOTE: some of these details are obtained from third party information.
References 7 Total
- securityfocus.com: 20071220 [Aria-Security.net] ABI Version 3.7.9.17 Remote SQL Injection mailing-list
- vupen.com: ADV-2007-4302 vdb-entry
- secunia.com: 28193 third-party-advisory
- http://aria-security.net/forum/showthread.php?p=1174
- osvdb.org: 39383 vdb-entry
- exchange.xforce.ibmcloud.com: aeries-lostpwd-sql-injection(39176) vdb-entry
- securityfocus.com: 26962 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- securityfocus.com: 20071220 [Aria-Security.net] ABI Version 3.7.9.17 Remote SQL Injection mailing-listx_transferred
- vupen.com: ADV-2007-4302 vdb-entryx_transferred
- secunia.com: 28193 third-party-advisoryx_transferred
- http://aria-security.net/forum/showthread.php?p=1174 x_transferred
- osvdb.org: 39383 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: aeries-lostpwd-sql-injection(39176) vdb-entryx_transferred
- securityfocus.com: 26962 vdb-entryx_transferred