SendStudio 4.0.1 - Cross-Site Scripting / Security Bypass
Author: indoushka
type: webapps
platform: php
port:
date_added: 2009-12-31
date_updated: 2014-05-21
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/37554/info
SendStudio (also called Email Marketer) is prone to a cross-site scripting issue and a security-bypass issue.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site steal cookie-based authentication credentials and gain unauthorized administrative access to the affected application.
The vendor reports that Interspire Email Marketer 6 is not affected.
1- XSS (High)
http://www.example.com/wl-ssf41/admin/index.php/index?SID=>"><ScRiPt%20%0a%0d>alert(213771818860)%3B</ScRiPt>
2- Bay Pass (Medium)
http://www.example.com/wl-ssf41/admin/index.php/index?SID=xx