PT-2011-3641 · Smartertools · Smarterstats

Publicado

2011-05-20

·

Atualizado

2017-08-29

·

CVE-2011-2153

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SmarterTools SmarterStats version 6.0
Description The issue allows context-dependent attackers to discover credentials by reading web-server access logs, web-server Referer logs, or the browser history, due to the support of URLs containing txtUser and txtPass parameters in the query string in the Login.aspx page. This is related to a "cross-domain Referer leakage" issue.
Recommendations For SmarterTools SmarterStats version 6.0, consider restricting access to the Login.aspx page to minimize the risk of exploitation, and avoid using the txtUser and txtPass parameters in the query string until the issue is resolved.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2153

Produtos afetados

Smarterstats