OS Command Injection Vulnerability in SmarterStats Web Server by SmarterTools
CVE-2011-2148
Currently unrated
What is CVE-2011-2148?
The SmarterStats 6.0 web server by SmarterTools is susceptible to an OS command injection vulnerability that allows remote attackers to execute arbitrary commands. This security issue arises through specific parameters within the admin page (frmSite.aspx), including improperly sanitized inputs such as cookies and form parameters. Attackers can exploit this weakness by crafting requests that leverage leading and trailing ampersand characters, enabling them to manipulate command execution in an unauthorized manner, potentially leading to severe security breaches.
References
EPSS Score
12% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved