CVE-2011-3688

Sonexis ConferenceManager 9.3.14.0 - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Sonexis ConferenceManager 9.3.14.0 allow remote attackers to execute arbitrary SQL commands via (1) the g parameter to Conference/Audio/AudioResourceContainer.asp or (2) the txtConferenceID parameter to Login/HostLogin.asp.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8401

Scores

EPSS 0.0109
EPSS Percentile 61.9%

Details

CWE
CWE-89
Status published
Products (1)
sonexis/conferencemanager 9.3.14.0
Published Sep 27, 2011
Tracked Since Feb 18, 2026