Loading
Generated remediation guidance and an executive summary. No account required.
login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
Use CWE-200, Smartertools vendor hub and Smarterstats product page to widen CVE-2011-2154 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2011-4752, CVE-2011-2159 and CVE-2011-2158 for nearby disclosures in the same product family.