Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
257 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.85% | — | Smartertools Smarterstats | 16/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SmarterTools SmarterStats 6.2.4100 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Default.aspx and certain other files. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ut-files Utstats | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ut-files Utstats | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Joerg Risse Dnet Live-stats | 5/10/2011 | 16/6/2026 | Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the showlang parameter. | |
| Modificada | Alta (10) | 4.4% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The SmarterTools SmarterStats 6.0 web server omits the Content-Type header for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving (1) Admin/Defaults/frmDefaultSiteSettings.aspx, (2) Admin/Defaults/frmServerDefaults.aspx, (3)… | |
| Modificada | Alta (10) | 4.4% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The SmarterTools SmarterStats 6.0 web server sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving (1) Admin/frmSite.aspx, (2) Admin/frmSites.aspx, (3) Admin/frmViewReports.aspx, (4)… | |
| Modificada | Media (5) | 2.6% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The (1) Admin/frmEmailReportSettings.aspx and (2) Admin/frmGeneralSettings.aspx components in the SmarterTools SmarterStats 6.0 web server generate web pages containing e-mail addresses, which allows remote attackers to obtain potentially sensitive information by reading the default values of form fields. | |
| Modificada | Media (5) | 2.6% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The SmarterTools SmarterStats 6.0 web server allows remote attackers to obtain directory listings via a direct request for the (1) Admin/, (2) Admin/Defaults/, (3) Admin/GettingStarted/, (4) Admin/Popups/, (5) App_Themes/, (6) Client/, (7) Client/Popups/, (8) Services/, (9) Temp/, (10) UserControls/, (11)… | |
| Modificada | Alta (7.5) | 3.9% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation. | |
| Modificada | Media (5) | 2.7% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | login.aspx in the SmarterTools SmarterStats 6.0 web server does not include the HTTPOnly flag in a Set-Cookie header for the loginsettings cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (5) | 2.0% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | Login.aspx in the SmarterTools SmarterStats 6.0 web server supports URLs containing txtUser and txtPass parameters in the query string, which makes it easier for context-dependent attackers to discover credentials by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, related… | |
| Modificada | Media (5) | 2.6% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The SmarterTools SmarterStats 6.0 web server generates web pages containing external links in response to GET requests with query strings for (1) Client/frmViewReports.aspx or (2) UserControls/Popups/frmHelp.aspx, which makes it easier for remote attackers to obtain sensitive information by reading (a) web-server… | |
| Modificada | Media (5) | 2.7% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The (1) Admin/frmEmailReportSettings.aspx, (2) Admin/frmGeneralSettings.aspx, (3) Admin/frmSite.aspx, (4) Client/frmUser.aspx, and (5) Login.aspx components in the SmarterTools SmarterStats 6.0 web server accept cleartext passwords, which makes it easier for remote attackers to obtain sensitive information by sniffing… | |
| Modificada | Media (5) | 3.0% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | The SmarterTools SmarterStats 6.0 web server does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error and daemon pause) via vectors involving (1) certain cookies in a SiteInfoLookup action to Admin/frmSites.aspx,… | |
| Modificada | Alta (7.5) | 2.4% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in the SmarterTools SmarterStats 6.0 web server allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) Admin/frmSite.aspx, (2) Default.aspx, (3) Services/SiteAdmin.asmx, or (4) Client/frmViewReports.aspx; certain cookies to (5)… | |
| Modificada | Alta (10) | 5.3% | — | Smartertools Smarterstats | 20/5/2011 | 16/6/2026 | Admin/frmSite.aspx in the SmarterTools SmarterStats 6.0 web server allows remote attackers to execute arbitrary commands via vectors involving a leading and trailing & (ampersand) character, and (1) an STTTState cookie, (2) the ctl00%24MPH%24txtAdminNewPassword_SettingText parameter, (3) the… | |
| Modificada | Media (6.4) | 2.7% | — | Awstats | 2/12/2010 | 16/6/2026 | Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory. | |
| Modificada | Alta (7.5) | 2.5% | — | Awstats | 2/12/2010 | 16/6/2026 | awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Awstats | 2/12/2010 | 16/6/2026 | awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server. | |
| Modificada | Media (5.8) | 3.5% | 💥 Exploit | Awstats | 2/12/2010 | 16/6/2026 | Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Smartertools Smarterstats | 16/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Wapplersystems WS Stats | 22/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Visitor Tracking (ws_stats) extension before 0.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 3.2% | — | Tatsuhiro Tsujikawa Aria2 | 17/5/2010 | 16/6/2026 | Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Clausvb DL Stats | 23/4/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php. | |
| Modificada | Media (4.3) | 2.4% | 💥 Exploit | Clausvb DL Stats | 23/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. |