Loading
Generated remediation guidance and an executive summary. No account required.
Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related to a "cross-domain Referer leakage" issue.
Use CWE-200, Smartertools vendor hub and Smarterstats product page to widen CVE-2011-2153 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2011-4752, CVE-2011-2159 and CVE-2011-2158 for nearby disclosures in the same product family.