Aeries develops a focused line of student information and administrative management systems deployed across K-12 school districts, with its primary exposure centered on the Aeries Student Information System and Browser Interface products. The recurring vulnerability profile reflects the web-facing and data-handling role of these applications, clustering around SQL injection and cross-site scripting weaknesses that are endemic to web application input handling and are characteristic of systems processing sensitive educational records. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aeries over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0943HIGH Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to | Feb 25, 2008 | 7.5 | 31 | NO | YES |
CVE-2008-0942HIGH SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the Grd | Feb 25, 2008 | 7.5 | 30 | NO | YES |
CVE-2007-6517HIGH SQL injection vulnerability in the forget password section (LostPwd.asp) in Eagle Software Aeries Browser Interface (ABI) 3.7.9.17 allows remote attackers to execute arbitrary SQL | Dec 24, 2007 | 7.5 | 19 | NO | NO |
CVE-2008-1549MEDIUM Multiple SQL injection vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to execute arbitrary SQL | Mar 31, 2008 | 6.8 | 18 | NO | NO |
CVE-2008-0941MEDIUM Cross-site scripting (XSS) vulnerability in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to inject arbitrary web script or HTML via an ev | Feb 25, 2008 | 4.3 | 16 | NO | NO |
CVE-2008-1548MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to inject a | Mar 31, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aeries.
Media articles that mention a CVE ID that affects a product developed by Aeries — matched by CVE ID, not by vendor name.