Security Advisory

CVE-2011-2153

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-05-20 22:00:00
Last updated 2024-08-06 22:53:17
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.