SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-2153

Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs,…

MEDIUM 5.0EPSS 2.01%

Does this matter?

Lower severity and a low EPSS score (2.01%). Track it; it rarely justifies an emergency change on its own.

Description

Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.01% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
smartertools/smarterstats
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.