Information Disclosure in Parallels Plesk Panel Control Panel
CVE-2011-4736

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4736?

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 is susceptible to an information disclosure vulnerability, allowing remote attackers to intercept sensitive password information. This occurs when user credentials are transmitted over an unsecured HTTP connection, exposing them to potential network sniffing attacks. Vulnerable files, such as login_up.php3, facilitate this exposure, making it imperative for users to upgrade to more secure versions or implement encryption measures.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.