← Vulnerability feed

Vulnerability record · CVE-2011-2150 · published 20 May 2011

CVE-2011-2150: Smartertools smarterstats improper input validation vulnerability

Smartertools · Smarterstats

The SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error and daemon pause) via vectors involving (1) certain cookies in a SiteInfoLookup action to Admin/frmSites.aspx, or certain (2) cookies or (3) parameters to (a) Client/frmViewOverviewReport.aspx, (b) Client/frmViewReports.aspx, or (c) Services/SiteAdmin.asmx, as demonstrated by a ]]>> string, related to an "XML injection" issue.

5.0 CVSS 2.0 Medium EPSS 3.0% · top 13.0% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

The SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error and daemon pause) via vectors involving (1) certain cookies in a SiteInfoLookup action to Admin/frmSites.aspx, or certain (2) cookies or (3) parameters to (a) Client/frmViewOverviewReport.aspx, (b) Client/frmViewReports.aspx, or (c) Services/SiteAdmin.asmx, as demonstrated by a ]]>> string, related to an "XML injection" issue.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2150 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4752Smartertools smarterstats vulnerabilitySmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecif…EPSS 1.8%10.0CVE-2011-2148Smartertools smarterstats os command injection vulnerabilityAdmin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a lead…EPSS 5.3%10.0CVE-2011-2158Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have a…EPSS 4.4%10.0CVE-2011-2159Smartertools smarterstats vulnerabilityThe SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspe…EPSS 4.4%7.5CVE-2011-2149Smartertools smarterstats sql injection vulnerabilityMultiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via c…EPSS 2.4%7.5CVE-2011-2155Smartertools smarterstats improper authentication vulnerabilityLogin.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete f…EPSS 3.9%6.1CVE-2017-14620Smartertools smarterstats cross-site scripting vulnerabilitySmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cro…EPSS 2.5%5.0CVE-2011-4751Smartertools smarterstats information exposure vulnerabilitySmarterTools SmarterStats 6.2.4100 generates web pages containing external links in response to GET requests with query strings for frmGettingStarted…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2011-2150), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.