CVE-2011-4801

Authenex Strong Authentication System Server 3.1.0.2-3.1.0.3 SQL Injection via Username Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4801. PoCs published by Jose Carlos de Arriba.

AI-analyzed exploit summary This is a security advisory detailing a time-based SQL injection vulnerability in Authenex A-Key/ASAS Web Management Control 3.1.0.2. The PoC demonstrates the vulnerability via a crafted POST request with a SQL injection payload.

Description

SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

Exploits (1)

exploitdb WRITEUP
by Jose Carlos de Arriba · textwebappsmultiple
https://www.exploit-db.com/exploits/18117

This is a security advisory detailing a time-based SQL injection vulnerability in Authenex A-Key/ASAS Web Management Control 3.1.0.2. The PoC demonstrates the vulnerability via a crafted POST request with a SQL injection payload.

Classification
Writeup 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Authenex Web Management Console 3.1.0.2, Authenex ASAS 3.1.0.2, Authenex ASAS 3.1.0.3
No auth needed
Prerequisites: Network access to the Authenex Web Management portal
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.0123
EPSS Percentile 65.2%

Details

CWE
CWE-89
Status published
Products (2)
authenex/authenex_strong_authentication_system_server 3.1.0.2
authenex/authenex_strong_authentication_system_server 3.1.0.3
Published Dec 14, 2011
Tracked Since Feb 18, 2026