Security Advisory

CVE-2011-2155

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-05-20 22:00:00
Last updated 2024-08-06 22:53:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.