← Vulnerability feed

Vulnerability record · CVE-2011-2148 · published 20 May 2011

CVE-2011-2148: Smartertools smarterstats os command injection vulnerability

Smartertools · Smarterstats

Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie, (2) the ctl00%24MPH%24txtAdminNewPassword_SettingText parameter, (3) the ctl00%24MPH%24txtSmarterLogDirectory parameter, (4) the ctl00%24MPH%24ucSiteSeoSearchEngineSettings%24chklistEngines_SettingCheckBox%2414 parameter, (5) the ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter, or (6) the ctl00_MPH_grdLogLocations_HiddenLSR parameter, related to an "OS command injection" issue.

10.0 CVSS 2.0 High EPSS 5.3% · top 7.7% CWE-78 · OS command injection
10.0CVSS 2.0 base score
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie, (2) the ctl00%24MPH%24txtAdminNewPassword_SettingText parameter, (3) the ctl00%24MPH%24txtSmarterLogDirectory parameter, (4) the ctl00%24MPH%24ucSiteSeoSearchEngineSettings%24chklistEngines_SettingCheckBox%2414 parameter, (5) the ctl00%24MPH%24ucSiteSeoSettings%24txtSeoMaxKeywords_SettingText parameter, or (6) the ctl00_MPH_grdLogLocations_HiddenLSR parameter, related to an "OS command injection" issue.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2148 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4752Smartertools smarterstats vulnerabilitySmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecif…EPSS 1.8%10.0CVE-2011-2158Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have a…EPSS 4.4%10.0CVE-2011-2159Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspe…EPSS 4.4%7.5CVE-2011-2149Smartertools smarterstats sql injection vulnerabilityMultiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via c…EPSS 2.4%7.5CVE-2011-2155Smartertools smarterstats improper authentication vulnerabilityLogin.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete f…EPSS 3.9%6.1CVE-2017-14620Smartertools smarterstats cross-site scripting vulnerabilitySmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cro…EPSS 2.5%5.0CVE-2011-4751Smartertools smarterstats information exposure vulnerabilitySmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted…EPSS 1.1%5.0CVE-2011-2150Smartertools smarterstats improper input validation vulnerabilityThe SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows rem…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2011-2148), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.