Portrait Software Portrait Campaign Manager Multiple Cross Site Scripting Vulnerabilities
BID:38252
Info
Portrait Software Portrait Campaign Manager Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 38252 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2010 12:00AM |
| Updated: | Feb 16 2010 12:00AM |
| Credit: | Roel Schouten from the FortConsult Security Research Team |
| Vulnerable: |
Portrait Software Portrait Campaign Manager 4.6.1.22 |
| Not Vulnerable: |
Portrait Software Portrait Campaign Manager 4.6.x SP3 |
Discussion
Portrait Software Portrait Campaign Manager Multiple Cross Site Scripting Vulnerabilities
Portrait Campaign Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Portrait Campaign Manager 4.6.1.22 is vulnerable; other versions prior to 4.6 SP3 may also be affected.
Portrait Campaign Manager is prone to multiple cross-site scripting vulnerabilities because it fails to sufficiently sanitize user-supplied data.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Portrait Campaign Manager 4.6.1.22 is vulnerable; other versions prior to 4.6 SP3 may also be affected.
Exploit / POC
Portrait Software Portrait Campaign Manager Multiple Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI is available:
Solution / Fix
Portrait Software Portrait Campaign Manager Multiple Cross Site Scripting Vulnerabilities
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Portrait Software Portrait Campaign Manager Multiple Cross Site Scripting Vulnerabilities
References:
References:
- Portrait Campaign Manager Homepage (Portrait Software)
- Portrait Million Handshakes Cross-Site scripting Vulnerability (FortConsult)