Information Disclosure Risk in SmarterStats Web Server by SmarterTools
CVE-2011-2153
Currently unrated
What is CVE-2011-2153?
The vulnerability in SmarterStats 6.0 allows attackers to extract user credentials via the txtUser and txtPass parameters in the query string. This exposure can lead to context-dependent attacks where sensitive information is revealed through web-server logs, including access logs and Referer logs, or even from the browser's history. Thus, it elevates the risk of unauthorized access to user accounts.
References
Timeline
Vulnerability published
Vulnerability Reserved