Eagle · Eagle Software Aeries Browser Interface · CVE-2008-0943
**Name of the Vulnerable Software and Affected Versions**
Eagle Software Aeries Browser Interface (ABI) version 3.7.2.2
**Description**
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the `FC` parameter to "Comments.asp", or the `Term` parameter to either "Labels.asp" or "ClassList.asp".
**Recommendations**
For version 3.7.2.2, consider restricting access to the affected API endpoints "Comments.asp", "Labels.asp", and "ClassList.asp" to minimize the risk of exploitation. Avoid using the `FC` and `Term` parameters in these endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.