First published: Fri May 20 2011(Updated: )
The (1) Admin/frmEmailReportSettings.aspx and (2) Admin/frmGeneralSettings.aspx components in the SmarterTools SmarterStats 6.0 web server generate web pages containing e-mail addresses, which allows remote attackers to obtain potentially sensitive information by reading the default values of form fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterStats | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2157 is classified as a moderate severity vulnerability due to the exposure of potentially sensitive email addresses.
To fix CVE-2011-2157, it is recommended to update SmarterStats to a version that does not expose email addresses in the web pages.
The components affected by CVE-2011-2157 are Admin/frmEmailReportSettings.aspx and Admin/frmGeneralSettings.aspx in SmarterStats 6.0.
CVE-2011-2157 allows remote attackers to obtain the default values of form fields, which may include sensitive email addresses.
CVE-2011-2157 was published on June 23, 2011.