Parallels
Parallels Plesk Small Business Panel: vulnerabilidades y CVE
Parallels Plesk Small Business Panel tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2011-4768 | Alta (10) | 1.9% | — | 16 dic 2011 | The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified… |
| CVE-2011-4767 | Media (5) | 1.1% | — | 16 dic 2011 | The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which… |
| CVE-2011-4766 | Media (5) | 1.1% | — | 16 dic 2011 | The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a direct request to wysiwyg/fckconfig.js. NOTE: CVE disputes this issue… |
| CVE-2011-4765 | Media (4.3) | 0.97% | — | 16 dic 2011 | The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain… |
| CVE-2011-4764 | Media (4.3) | 0.84% | — | 16 dic 2011 | Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted… |
| CVE-2011-4763 | Alta (7.5) | 1.0% | — | 16 dic 2011 | Multiple SQL injection vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP… |
| CVE-2011-4762 | Alta (10) | 1.8% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving… |
| CVE-2011-4761 | Alta (10) | 1.8% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation… |
| CVE-2011-4760 | Media (5) | 1.1% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially… |
| CVE-2011-4759 | Media (5) | 1.1% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes… |
| CVE-2011-4758 | Media (5) | 1.1% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by forms in smb/auth and… |
| CVE-2011-4757 | Alta (10) | 2.2% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended… |
| CVE-2011-4756 | Media (5) | 1.1% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script… |
| CVE-2011-4755 | Alta (10) | 1.8% | — | 16 dic 2011 | Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly… |
| CVE-2011-4754 | Media (4.3) | 0.84% | — | 16 dic 2011 | Multiple cross-site scripting (XSS) vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by… |
| CVE-2011-4753 | Alta (7.5) | 1.0% | — | 16 dic 2011 | Multiple SQL injection vulnerabilities in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by… |