Description
Multiple cross-site scripting (XSS) vulnerabilities in Sonexis ConferenceManager 9.2.11.0 allow remote attackers to inject arbitrary web script or HTML via (1) the txtConferenceID parameter to HostLogin.asp, (2) the txtConferenceID parameter to ParticipantLogin.asp, (3) the acp parameter to ForgotPIN.asp, or the (4) Description, (5) title, or (6) Heading parameter to Error.asp.
References (2)
Core 2
Core References
Exploit x_refsource_misc
http://www.solutionary.com/index/SERT/Vuln-Disclosures/Sonexis-XSS-Vulnerabilities.html
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/8400
Scores
EPSS
0.0087
EPSS Percentile
55.1%
Details
CWE
CWE-79
Status
published
Products (1)
sonexis/conferencemanager
9.2.11.0
Published
Sep 27, 2011
Tracked Since
Feb 18, 2026