SendStudio Cross Site Scripting and Security Bypass Vulnerabilities
BID:37554
Info
SendStudio Cross Site Scripting and Security Bypass Vulnerabilities
| Bugtraq ID: | 37554 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2009 12:00AM |
| Updated: | Jan 11 2010 04:31PM |
| Credit: | indoushka |
| Vulnerable: |
Interspire SendStudio 4.0.1 |
| Not Vulnerable: |
Interspire Email Marketer 6 |
Discussion
SendStudio Cross Site Scripting and Security Bypass Vulnerabilities
SendStudio (also called Email Marketer) is prone to a cross-site scripting issue and a security-bypass issue.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site steal cookie-based authentication credentials and gain unauthorized administrative access to the affected application.
The vendor reports that Interspire Email Marketer 6 is not affected.
SendStudio (also called Email Marketer) is prone to a cross-site scripting issue and a security-bypass issue.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site steal cookie-based authentication credentials and gain unauthorized administrative access to the affected application.
The vendor reports that Interspire Email Marketer 6 is not affected.
Exploit / POC
SendStudio Cross Site Scripting and Security Bypass Vulnerabilities
Attackers may exploit these issues through a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
Attackers may exploit these issues through a browser. To exploit a cross-site scripting issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URIs are available:
Solution / Fix
SendStudio Cross Site Scripting and Security Bypass Vulnerabilities
Solution:
Updates are available; please contact the vendor for more information.
Solution:
Updates are available; please contact the vendor for more information.
References
SendStudio Cross Site Scripting and Security Bypass Vulnerabilities
References:
References:
- Email Marketer Homepage (InterSpire)
- Interspire Homepage (Interspire)