| Solutionary ID: SERT-VDN-1006 |
| CVE ID: CVE-2011-3688 |
| Product:Sonexis ConferenceManager |
| Application Vendor: Sonexis |
| Vendor URL: http://www.sonexis.com/products/index.asp |
| Date discovered: 1/27/2011 |
| Discovered by: Rob Kraus, Paul Petefish and Solutionary Engineering Research Team (SERT) |
| Vendor notification date: 2/18/2011 |
| Vendor response date: 3/02/2011 |
| Vendor acknowledgment date: 3/02/2011 |
Public disclosure date: 4/06/2011 Exploit Vectors: Local and Remote The following parameters and web pages have been tested and verified; however, it is possible more views and parameters within the application are vulnerable: Standard SQL Injection (Error-based) Conference/Audio/AudioResourceContainer.asp (g) parameter Blind SQL Injection Login/HostLogin.asp (txtConferenceID) parameter Tested on:Windows Server 2003 RC2 (SP2) with Sonexis ConferenceManager version 9.3.14.0 Affected software versions:Sonexis ConferenceManager version 9.3.14.0 (previous versions may also be vulnerable) Impact: Successful attacks could disclose sensitive records contained within the database such as user, session, and application information to the attacker, resulting in a loss of confidentiality. Fixed in: No Fix Available Remediation guidelines: Restrict access to the application via the public internet. Monitor vendor communications for notification of patch availability. |
- Trusted Managed Security Provider | Solutionary
- Research
- Vulnerability Disclosures
- Sonexis ConferenceManager SQL Injection

