{"api_version":"1","generated_at":"2026-07-23T01:34:03+00:00","cve":"CVE-2011-4801","urls":{"html":"https://cve.report/CVE-2011-4801","api":"https://cve.report/api/cve/CVE-2011-4801.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-4801","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-4801"},"summary":{"title":"CVE-2011-4801","description":"SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-12-14 00:55:02","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-89","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection","name":"http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Authenex A-Key & ASAS Web Management Control 3.1.0.2 - Time-based SQL Injection","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/18117","name":"http://www.exploit-db.com/exploits/18117","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Authenex A-Key/ASAS Web Management Control 3.1.0.2 (latest) - Time-based SQL Injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2","name":"https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-4801","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4801","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"4801","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"authenex","cpe5":"authenex_strong_authentication_system_server","cpe6":"3.1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"4801","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"authenex","cpe5":"authenex_strong_authentication_system_server","cpe6":"3.1.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:16:34.974Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"18117","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/18117"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-12-14T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"18117","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/18117"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2"},{"tags":["x_refsource_MISC"],"url":"http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-4801","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"18117","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/18117"},{"name":"https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2","refsource":"CONFIRM","url":"https://support.authenex.com/index.php?/Knowledgebase/Article/View/124/0/asas3103update2"},{"name":"http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection","refsource":"MISC","url":"http://www.foregroundsecurity.com/security-advisories/101-authenex-a-keyasas-web-management-control-3102-time-based-sql-injection"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-4801","datePublished":"2011-12-14T00:00:00.000Z","dateReserved":"2011-12-13T00:00:00.000Z","dateUpdated":"2024-09-16T17:28:46.594Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-12-14 00:55:02","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-89","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:authenex:authenex_strong_authentication_system_server:3.1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"83ADC61E-8408-4977-B56E-451ED1A970D8"},{"vulnerable":true,"criteria":"cpe:2.3:a:authenex:authenex_strong_authentication_system_server:3.1.0.3:*:*:*:*:*:*:*","matchCriteriaId":"2952CD6C-D3A0-4E13-9C5E-3EF268D5AFDA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"4801","Ordinal":"1","Title":"CVE-2011-4801","CVE":"CVE-2011-4801","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"4801","Ordinal":"1","NoteData":"SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authentication System (ASAS) Server 3.1.0.2 and 3.1.0.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.","Type":"Description","Title":"CVE-2011-4801"},{"CveYear":"2011","CveId":"4801","Ordinal":"2","NoteData":"2011-12-13","Type":"Other","Title":"Published"}]}}}