CVE-2011-2156: Infoleak
The SmarterTools SmarterStats 6.0 web server allows remote attackers to obtain directory listings via a direct request for the (1) Admin/, (2) Admin/Defaults/, (3) Admin/GettingStarted/, (4) Admin/Popups/, (5) AppThemes/, (6) Client/, (7) Client/Popups/, (8) Services/, (9) Temp/, (10) UserControls/, (11) UserControls/PanelBarTemplates/, (12) UserControls/Popups/, (13) aspnetclient/, or (14) aspnetclient/systemweb/ directory name, or (15) certain directory names under AppThemes/Default/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2156?
CVE-2011-2156 is classified as a high-severity vulnerability due to its potential for unauthorized access to sensitive directories.
How do I fix CVE-2011-2156?
To fix CVE-2011-2156, restrict access to sensitive directories and implement proper authentication mechanisms.
What are the implications of CVE-2011-2156?
CVE-2011-2156 allows remote attackers to access directory listings, potentially exposing sensitive files and information.
Is CVE-2011-2156 being actively exploited?
There have been reports of CVE-2011-2156 being targeted by attackers, making it important to address the vulnerability promptly.
Which versions of SmarterStats are affected by CVE-2011-2156?
CVE-2011-2156 specifically affects SmarterTools SmarterStats version 6.0.