HIGH · 7.5

CVE-2011-5262

SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

Vulnerability Description

SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
SonicwallAventail Sra Ex Virtual Appliance-
SonicwallAventail Sra Ex6000-
SonicwallAventail Sra Ex7000-
SonicwallAventail Sra Ex9000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-5262?

CVE-2011-5262 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

How severe is CVE-2011-5262?

CVE-2011-5262 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-5262?

Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Aventail Sra Ex Virtual Appliance, Sonicwall Aventail Sra Ex6000, Sonicwall Aventail Sra Ex7000, Sonicwall Aventail Sra Ex9000.