First published: Tue Feb 12 2013(Updated: )
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Aventail SRA EX Virtual Appliance | ||
Sonicwall Sra Ex6000 | ||
Sonicwall SRA EX7000 | ||
Sonicwall SRA EX9000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5262 is rated as a high severity vulnerability due to its potential for remote SQL injection attacks.
To fix CVE-2011-5262, ensure that your SonicWALL Aventail software is updated to the latest version where this vulnerability has been patched.
The potential impacts of CVE-2011-5262 include unauthorized access to the database and execution of arbitrary SQL commands.
CVE-2011-5262 affects SonicWALL Aventail SRA EX Virtual Appliance, SRA EX6000, SRA EX7000, and SRA EX9000.
CVE-2011-5262 can be exploited by remote attackers who can send crafted requests to the vulnerable software.