CVE-2011-2148: Command Injection
Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie, (2) the ctl00%24MPH%24txtAdminNewPasswordSettingText parameter, (3) the ctl00%24MPH%24txtSmarterLogDirectory parameter, (4) the ctl00%24MPH%24ucSiteSeoSearchEngineSettings%24chklistEnginesSettingCheckBox%2414 parameter, (5) the ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywordsSettingText parameter, or (6) the ctl00MPHgrdLogLocationsHiddenLSR parameter, related to an "OS command injection" issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2148?
CVE-2011-2148 is considered critical due to its ability to allow remote command execution.
How do I fix CVE-2011-2148?
To fix CVE-2011-2148, update to a non-vulnerable version of SmarterStats that addresses this security issue.
What are the impacts of CVE-2011-2148 on affected systems?
CVE-2011-2148 can lead to unauthorized command execution, potentially compromising system integrity and confidentiality.
Which versions of SmarterStats are affected by CVE-2011-2148?
CVE-2011-2148 affects SmarterTools SmarterStats version 6.0.
Is CVE-2011-2148 a local or remote attack vector?
CVE-2011-2148 is a remote attack vector that allows external attackers to exploit the vulnerability.