Lucene search

K
exploitdbAsheesh kumarEDB-ID:18122
HistoryNov 16, 2011 - 12:00 a.m.

SonicWALL Aventail SSL-VPN - SQL Injection

2011-11-1600:00:00
Asheesh kumar
www.exploit-db.com
31

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

34.8%

 ================================================================================
 
                      SonicWALL Aventail  SSL-VPN  SQL Injection Vulnerability
                     ================================================================================
 

#Date- 17/11/11

# code by Asheesh kumar Mani Tripathi
 
     
 
# Credit by Asheesh Anaconda
 
 
 
#Vulnerbility
SonicWALL Aventail  SSL-VPN  is prone to an SQL-injection vulnerability because the application fails to properly 
sanitize user-supplied input before using it in an SQL query.
 
#Impact
A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database
 
 
========================================================================================================================
 
                                                           Request
========================================================================================================================
 
https://example.xxx.com/prodpage.cfm?CFID=&CFTOKEN=&CategoryID=[SQL]

AI Score

7.4

Confidence

Low

EPSS

0.001

Percentile

34.8%

Related for EDB-ID:18122