CVE-2011-4856
- EPSS 0.75%
- Veröffentlicht 16.12.2011 11:55:13
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/h...
CVE-2011-4850
- EPSS 0.25%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to thi...
CVE-2011-4849
- EPSS 0.25%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http sessio...
CVE-2011-4848
- EPSS 0.25%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling...
CVE-2011-4847
- EPSS 0.17%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.
CVE-2011-4777
- EPSS 0.23%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html.
CVE-2011-4776
- EPSS 0.23%
- Veröffentlicht 16.12.2011 11:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/update...
- EPSS 0.24%
- Veröffentlicht 16.12.2011 11:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easier for remote attackers to conduct spoofing attacks by leveraging protocol weaknesses.
- EPSS 1.09%
- Veröffentlicht 16.12.2011 11:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended worksta...
- EPSS 0.23%
- Veröffentlicht 16.12.2011 11:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sens...