CVE-2011-2151
SmarterStats 6.0 - Cleartext Password Transmission in Multiple Admin and Client Pages
Title source: llmDescription
The (1) Admin/frmEmailReportSettings.aspx, (2) Admin/frmGeneralSettings.aspx, (3) Admin/frmSite.aspx, (4) Client/frmUser.aspx, and (5) Login.aspx components in the SmarterTools SmarterStats 6.0 web server accept cleartext passwords, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml-sqlinjection.html.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67831
Various Sources x_refsource_misc
http://xss.cx/examples/exploits/stored-reflected-xss-cwe79-smarterstats624100.html
US Government Resource x_refsource_misc
http://www.kb.cert.org/vuls/id/MORO-8GYQR4
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/240150
Scores
EPSS
0.0267
EPSS Percentile
84.2%
Details
CWE
CWE-310
Status
published
Products (1)
smartertools/smarterstats
6.0
Published
May 20, 2011
Tracked Since
Feb 18, 2026