CVE-2011-2150 describes a denial-of-service vulnerability in SmarterTools SmarterStats 6.0. The flaw stems from improper validation of string data intended for XML storage, allowing remote attackers to trigger parsing errors and daemon pauses. This can be achieved through specially crafted cookies or parameters in various web application components, such as Admin/frmSites.aspx or Client/frmViewOverviewReport.aspx. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P), this vulnerability is of medium severity. It can be exploited remotely with low attack complexity and no authentication, leading to a partial denial of service. There is no impact on confidentiality or integrity. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0CPE matchmatch criteria | cpe:2.3:a:smartertools:smarterstats:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.