Summary
SonicWALL Aventail is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Further research conducted by the vendor indicates this issue may not be a vulnerability affecting the application.
References
Severity
Classification
-
CVE CVE-2011-5262 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- AdaptBB Multiple Input Validation Vulnerabilities
- 3Com OfficeConnect VPN Firewall Default Password Security Bypass Vulnerability
- AWCM CMS Multiple Remote File Include Vulnerabilities
- Apache Axis2 Document Type Declaration Processing Security Vulnerability
- Athena Web Registration remote command execution flaw