SQL Injection Vulnerabilities in SmarterStats Web Server by SmarterTools
CVE-2011-2149
Currently unrated
What is CVE-2011-2149?
Multiple SQL injection vulnerabilities have been identified in the SmarterTools SmarterStats 6.0 web server, enabling remote attackers to execute arbitrary SQL queries through various parameters. These inputs include the Admin/frmSite.aspx, Default.aspx, Services/SiteAdmin.asmx, and Client/frmViewReports.aspx pages. Additionally, vulnerabilities can be exploited via certain cookies, the Referer HTTP header, and the User-Agent HTTP header, particularly affecting the Services/SiteAdmin.asmx and login.aspx endpoints. This can lead to unauthorized access and manipulation of the underlying database.
References
Timeline
Vulnerability published
Vulnerability Reserved