CVE-2011-2155
SmarterStats 6.0 - Improper Authentication via Password Field Autocomplete
Title source: llmDescription
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.
References (5)
Core 5
Core References
Various Sources x_refsource_misc
http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml-sqlinjection.html.html
Various Sources x_refsource_misc
http://xss.cx/examples/exploits/stored-reflected-xss-cwe79-smarterstats624100.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67827
US Government Resource x_refsource_misc
http://www.kb.cert.org/vuls/id/MORO-8GYQR4
US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/240150
Scores
EPSS
0.0391
EPSS Percentile
89.0%
Details
CWE
CWE-287
Status
published
Products (1)
smartertools/smarterstats
6.0
Published
May 20, 2011
Tracked Since
Feb 18, 2026