Loading
Generated remediation guidance and an executive summary. No account required.
The SmarterTools SmarterStats 6.0 web server generates web pages containing external links in response to GET requests with query strings for (1) Client/frmViewReports.aspx or (2) UserControls/Popups/frmHelp.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (a) web-server access logs or (b) web-server Referer logs, related to a "cross-domain Referer leakage" issue.
Use CWE-200, Smartertools vendor hub and Smarterstats product page to widen CVE-2011-2152 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2011-4752, CVE-2011-2159 and CVE-2011-2158 for nearby disclosures in the same product family.