Vulnerability Description
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Aventail Sra Ex Virtual Appliance | - |
| Sonicwall | Aventail Sra Ex6000 | - |
| Sonicwall | Aventail Sra Ex7000 | - |
| Sonicwall | Aventail Sra Ex9000 | - |
Related Weaknesses (CWE)
References
- http://www.exploit-db.com/exploits/18122Exploit
- http://www.osvdb.org/77484Exploit
- http://www.securityfocus.com/bid/50702Exploit
- http://www.exploit-db.com/exploits/18122Exploit
- http://www.osvdb.org/77484Exploit
- http://www.securityfocus.com/bid/50702Exploit
FAQ
What is CVE-2011-5262?
CVE-2011-5262 is a vulnerability with a CVSS score of 7.5 (HIGH). SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
How severe is CVE-2011-5262?
CVE-2011-5262 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-5262?
Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Aventail Sra Ex Virtual Appliance, Sonicwall Aventail Sra Ex6000, Sonicwall Aventail Sra Ex7000, Sonicwall Aventail Sra Ex9000.