SQL Injection Vulnerabilities in SmarterStats Web Server by SmarterTools
CVE-2011-2149

Currently unrated

Key Information:

Vendor
CVE Published:
20 May 2011

What is CVE-2011-2149?

Multiple SQL injection vulnerabilities have been identified in the SmarterTools SmarterStats 6.0 web server, enabling remote attackers to execute arbitrary SQL queries through various parameters. These inputs include the Admin/frmSite.aspx, Default.aspx, Services/SiteAdmin.asmx, and Client/frmViewReports.aspx pages. Additionally, vulnerabilities can be exploited via certain cookies, the Referer HTTP header, and the User-Agent HTTP header, particularly affecting the Services/SiteAdmin.asmx and login.aspx endpoints. This can lead to unauthorized access and manipulation of the underlying database.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.