CVE-2011-3687

Sonexis ConferenceManager 9.2.11.0 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in Sonexis ConferenceManager 9.2.11.0 allow remote attackers to inject arbitrary web script or HTML via (1) the txtConferenceID parameter to HostLogin.asp, (2) the txtConferenceID parameter to ParticipantLogin.asp, (3) the acp parameter to ForgotPIN.asp, or the (4) Description, (5) title, or (6) Heading parameter to Error.asp.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8400

Scores

EPSS 0.0087
EPSS Percentile 54.7%

Details

CWE
CWE-79
Status published
Products (1)
sonexis/conferencemanager 9.2.11.0
Published Sep 27, 2011
Tracked Since Feb 18, 2026