Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-2153

Опубликовано: 20 мая 2011
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:smartertools:smarterstats:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00617
Низкий

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

github
больше 3 лет назад

Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.

EPSS

Процентиль: 69%
0.00617
Низкий

5 Medium

CVSS2

Дефекты

CWE-200