Summary
SonicWALL Aventail is prone to an SQL-injection vulnerability because the application fails to properly sanitize user-supplied input before using it in an SQL query.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database.
Further research conducted by the vendor indicates this issue may not be a vulnerability affecting the application.
References
Severity
Classification
-
CVE CVE-2011-5262 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- 68designs 68kb Multiple Remote File Include Vulnerabilities
- Adiscon LogAnalyzer Multiple SQL Injection and XSS Vulnerabilities
- Avenger's News System Command Execution
- 3Com OfficeConnect VPN Firewall Default Password Security Bypass Vulnerability
- Apache Struts2 Redirection and Security Bypass Vulnerabilities