VendorsSmarterToolssmarterstats6.2.4100
Vulnerabilities

SmarterTools SmarterStats 6.2.4100

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2011-4752
SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving frmCustomReport.aspx and certain other files. NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue.
Published 2011-12-16 · Modified
10.0EPSS 0.018
CVE-2011-4751
SmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.
Published 2011-12-16 · Modified
5.0EPSS 0.011
CVE-2011-4750
Multiple cross-site scripting (XSS) vulnerabilities in SmarterTools SmarterStats 6.2.4100 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Default.aspx and certain other files.
Published 2011-12-16 · Modified
4.3EPSS 0.009