← Vulnerability feed

Vulnerability record · CVE-2011-2149 · published 20 May 2011

CVE-2011-2149: Smartertools smarterstats sql injection vulnerability

Smartertools · Smarterstats

Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) Admin/frmSite.aspx, (2) Default.aspx, (3) Services/SiteAdmin.asmx, or (4) Client/frmViewReports.aspx; certain cookies to (5) Services/SiteAdmin.asmx or (6) login.aspx; the Referer HTTP header to (7) Services/SiteAdmin.asmx or (8) login.aspx; or (9) the User-Agent HTTP header to Services/SiteAdmin.asmx.

7.5 CVSS 2.0 High EPSS 2.4% · top 17.0% CWE-89 · SQL injection
7.5CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) Admin/frmSite.aspx, (2) Default.aspx, (3) Services/SiteAdmin.asmx, or (4) Client/frmViewReports.aspx; certain cookies to (5) Services/SiteAdmin.asmx or (6) login.aspx; the Referer HTTP header to (7) Services/SiteAdmin.asmx or (8) login.aspx; or (9) the User-Agent HTTP header to Services/SiteAdmin.asmx.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2149 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4752Smartertools smarterstats vulnerabilitySmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecif…EPSS 1.8%10.0CVE-2011-2148Smartertools smarterstats os command injection vulnerabilityAdmin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a lead…EPSS 5.3%10.0CVE-2011-2158Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have a…EPSS 4.4%10.0CVE-2011-2159Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspe…EPSS 4.4%7.5CVE-2011-2155Smartertools smarterstats improper authentication vulnerabilityLogin.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete f…EPSS 3.9%6.1CVE-2017-14620Smartertools smarterstats cross-site scripting vulnerabilitySmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cro…EPSS 2.5%5.0CVE-2011-4751Smartertools smarterstats information exposure vulnerabilitySmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted…EPSS 1.1%5.0CVE-2011-2150Smartertools smarterstats improper input validation vulnerabilityThe SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows rem…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2011-2149), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.