Information Disclosure Risk in SmarterStats Web Server by SmarterTools
CVE-2011-2153

Currently unrated

Key Information:

Vendor
CVE Published:
20 May 2011

What is CVE-2011-2153?

The vulnerability in SmarterStats 6.0 allows attackers to extract user credentials via the txtUser and txtPass parameters in the query string. This exposure can lead to context-dependent attacks where sensitive information is revealed through web-server logs, including access logs and Referer logs, or even from the browser's history. Thus, it elevates the risk of unauthorized access to user accounts.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.