CVE-2011-2155

SmarterStats 6.0 - Improper Authentication via Password Field Autocomplete

Title source: llm
STIX 2.1

Description

Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/67827
US Government Resource x_refsource_misc
http://www.kb.cert.org/vuls/id/MORO-8GYQR4
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/240150

Scores

EPSS 0.0391
EPSS Percentile 89.0%

Details

CWE
CWE-287
Status published
Products (1)
smartertools/smarterstats 6.0
Published May 20, 2011
Tracked Since Feb 18, 2026