CVE-2011-2153 Information
Feb 14, 2021
cve
Description
Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs (2) web-server Referer logs or (3) the browser history related to a \cross-domain Referer leakage\ issue.
Reference
http://www.kb.cert.org/vuls/id/240150 http://www.kb.cert.org/vuls/id/MORO-8GYQR4 http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml-sqlinjection.html.html https://exchange.xforce.ibmcloud.com/vulnerabilities/67829
Share on: