CVE-2011-2150
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error and daemon pause) via vectors involving (1) certain cookies in a SiteInfoLookup action to Admin/frmSites.aspx, or certain (2) cookies or (3) parameters to (a) Client/frmViewOverviewReport.aspx, (b) Client/frmViewReports.aspx, or (c) Services/SiteAdmin.asmx, as demonstrated by a ]]>> string, related to an "XML injection" issue.
El servidor web SmarterTools SmarterStats v6.0 no valida correctamente los datos de cadena que se destinan al almacenamiento de un documento XML, lo que permite a atacantes remotos provocar una denegación de servicio (error de análisis y pausa del demonio) a través de vectores que implican (1) a determinadas cookies en una acción SiteInfoLookup a Admin/frmSites.aspx, o ciertas (2) cookies o (3) los parámetros para a) Client/frmViewOverviewReport.aspx, (b) Client/frmViewReports.aspx, or (c) Services/SiteAdmin.asmx, como lo demuestra por una cadena ]]>>, en relación con un problema de "inyección de XML" .
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-05-20 CVE Reserved
- 2011-05-20 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.kb.cert.org/vuls/id/240150 | Third Party Advisory | |
http://www.kb.cert.org/vuls/id/MORO-8GYQR4 | Us Government Resource | |
http://xss.cx/examples/smarterstats-60-oscommandinjection-directorytraversal-xml-sqlinjection.html.html | X_refsource_misc | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/67832 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Smartertools Search vendor "Smartertools" | Smarterstats Search vendor "Smartertools" for product "Smarterstats" | 6.0 Search vendor "Smartertools" for product "Smarterstats" and version "6.0" | - |
Affected
|