CVE-2011-4856
- EPSS 1.76%
- Veröffentlicht 16.12.2011 11:55:13
- Zuletzt bearbeitet 16.06.2026 23:35:31
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/h...
CVE-2011-4850
- EPSS 1.07%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 16.06.2026 23:35:30
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to thi...
CVE-2011-4849
- EPSS 1.05%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 16.06.2026 23:35:30
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http sessio...
CVE-2011-4848
- EPSS 1.05%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 16.06.2026 23:35:30
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling...
CVE-2011-4847
- EPSS 0.69%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 16.06.2026 23:35:30
SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.
CVE-2011-4777
- EPSS 0.93%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 16.06.2026 23:35:23
Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html.
CVE-2011-4776
- EPSS 0.92%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 16.06.2026 23:35:23
Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/update...
- EPSS 1.03%
- Veröffentlicht 16.12.2011 11:55:10
- Zuletzt bearbeitet 16.06.2026 23:35:20
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easier for remote attackers to conduct spoofing attacks by leveraging protocol weaknesses.
- EPSS 2.38%
- Veröffentlicht 16.12.2011 11:55:10
- Zuletzt bearbeitet 16.06.2026 23:35:21
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended worksta...
- EPSS 1.16%
- Veröffentlicht 16.12.2011 11:55:10
- Zuletzt bearbeitet 16.06.2026 23:35:21
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sens...