Vulnerability Description
login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Smartertools | Smarterstats | 6.0 |
Related Weaknesses (CWE)
References
- http://www.kb.cert.org/vuls/id/240150US Government Resource
- http://www.kb.cert.org/vuls/id/MORO-8GYQR4US Government Resource
- http://xss.cx/examples/exploits/stored-reflected-xss-cwe79-smarterstats624100.ht
- http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67828
- http://www.kb.cert.org/vuls/id/240150US Government Resource
- http://www.kb.cert.org/vuls/id/MORO-8GYQR4US Government Resource
- http://xss.cx/examples/exploits/stored-reflected-xss-cwe79-smarterstats624100.ht
- http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67828
FAQ
What is CVE-2011-2154?
CVE-2011-2154 is a vulnerability with a CVSS score of 5.0 (MEDIUM). login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, which makes it easier for remote attackers to obtain ...
How severe is CVE-2011-2154?
CVE-2011-2154 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2154?
Check the references section above for vendor advisories and patch information. Affected products include: Smartertools Smarterstats.