OS Command Injection Vulnerability in SmarterStats Web Server by SmarterTools
CVE-2011-2148

Currently unrated

Key Information:

Vendor
CVE Published:
20 May 2011

What is CVE-2011-2148?

The SmarterStats 6.0 web server by SmarterTools is susceptible to an OS command injection vulnerability that allows remote attackers to execute arbitrary commands. This security issue arises through specific parameters within the admin page (frmSite.aspx), including improperly sanitized inputs such as cookies and form parameters. Attackers can exploit this weakness by crafting requests that leverage leading and trailing ampersand characters, enabling them to manipulate command execution in an unauthorized manner, potentially leading to severe security breaches.

References

EPSS Score

12% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.