First published: Fri May 20 2011(Updated: )
The SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving (1) Admin/frmSite.aspx, (2) Admin/frmSites.aspx, (3) Admin/frmViewReports.aspx, (4) App_Themes/AboutThisFolder.txt, (5) Client/frmViewReports.aspx, (6) Temp/AboutThisFolder.txt, (7) default.aspx, (8) login.aspx, or (9) certain .jpg URIs under Temp/. NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SmarterTools SmarterStats | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2158 has been rated as a medium severity vulnerability due to potential security implications from incorrect Content-Type headers.
To fix CVE-2011-2158, update to a newer version of SmarterStats that resolves the Content-Type header issue.
CVE-2011-2158 may allow remote attackers to exploit content interpretation conflicts, potentially leading to unauthorized access or manipulation.
CVE-2011-2158 specifically affects SmarterStats version 6.0 and may not impact other versions.
CVE-2011-2158 enables potential remote attacks by incorrectly setting Content-Type headers, which can lead to confusion in resource handling.