- EPSS 1.16%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 16.06.2026 23:35:22
Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in smb/auth and certain other files.
- EPSS 1.16%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 16.06.2026 23:35:22
Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote attackers t...
- EPSS 1.16%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 16.06.2026 23:35:22
Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by readin...
- EPSS 2%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 16.06.2026 23:35:22
Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving domains/sitebuild...
- EPSS 2%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 16.06.2026 23:35:22
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ a...
CVE-2011-4763
- EPSS 1.12%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 16.06.2026 23:35:22
Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by Wizard/E...