18117exploit
http://www.exploit-db.com/exploits/18117 CVE-2011-4801
Authenex A-Key/ASAS Web Management Control 3.1.0.2 - Blind SQL Injection
Record summary
CVE-2011-4801 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAuthenex A-Key/ASAS Web Management Control 3.1.0.2 - Blind SQL InjectionExploitDB exploitby Jose Carlos de ArribaNot analyzed1 file
References
4foregroundsecurity.com
http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-4801 support.authenex.comConfirmation
https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2