CVE-2011-2155

SmarterStats 6.0 - CSRF

Title source: llm

Description

Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.

Scores

EPSS 0.0266
EPSS Percentile 85.6%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

smartertools/smarterstats

Timeline

Published May 20, 2011
Tracked Since Feb 18, 2026