- EPSS 0.25%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in smb/auth and certain other files.
- EPSS 0.23%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote attackers t...
- EPSS 0.23%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by readin...
- EPSS 1.8%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving domains/sitebuild...
- EPSS 1.8%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ a...
CVE-2011-4763
- EPSS 0.31%
- Veröffentlicht 16.12.2011 11:55:11
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by Wizard/E...