CVE-2011-2155: High severity smartertools smarterstats vulnerability
Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2155?
CVE-2011-2155 is classified as a medium severity vulnerability due to the risk of authentication bypass.
How do I fix CVE-2011-2155?
To fix CVE-2011-2155, disable the autocomplete feature for the password field in the Login.aspx page.
Which software is affected by CVE-2011-2155?
CVE-2011-2155 affects SmarterTools SmarterStats version 6.0.
What type of vulnerability is CVE-2011-2155?
CVE-2011-2155 is a web application vulnerability that can allow remote attackers to bypass authentication on an unattended workstation.
Is CVE-2011-2155 still a concern today?
Although CVE-2011-2155 was identified over a decade ago, systems still running SmarterTools SmarterStats 6.0 may remain at risk if not patched.