Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2011-2145 Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T22:53:17.056Z

Reserved: 2011-05-20T00:00:00

Link: CVE-2011-2153

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-05-20T22:55:05.703

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-2153

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses