7.5
CVE-2011-2155
- EPSS 3.91%
- Veröffentlicht 20.05.2011 22:55:05
- Zuletzt bearbeitet 16.06.2026 23:30:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SmarterTools ≫ Smarterstats Version6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.91% | 0.889 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://www.kb.cert.org/vuls/id/240150
http://www.kb.cert.org/vuls/id/MORO-8GYQR4
http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml-sqlinjection.html.html
http://xss.cx/examples/exploits/stored-reflected-xss-cwe79-smarterstats624100.html
https://exchange.xforce.ibmcloud.com/vulnerabilities/67827