First published: Sat Sep 15 2012(Updated: )
SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2 allows remote attackers to execute arbitrary SQL commands via the scheduleID parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SonicWall ViewPoint | =6.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5169 is classified as a high-severity SQL injection vulnerability.
To fix CVE-2011-5169, update SonicWall ViewPoint to the latest version or apply provided patches.
Attackers can execute arbitrary SQL commands against the database via the scheduleID parameter.
CVE-2011-5169 affects SonicWall ViewPoint version 6.0 SP2.
Mitigation includes validating user input and employing web application firewalls to detect SQL injection attempts.