Cookie Security Flaw in Parallels Plesk Panel
CVE-2011-4728

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4728?

The Server Administration Panel in Parallels Plesk Panel version 10.2.0 may expose sensitive cookies, as it fails to set the secure flag during HTTPS sessions. This oversight allows attackers to capture these cookies by monitoring unencrypted HTTP traffic. The vulnerability can affect critical authentication processes, potentially leading to unauthorized access and data breaches.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2011-4728 : Cookie Security Flaw in Parallels Plesk Panel