Password Form Weakness in Parallels Plesk Panel 10.2.0
CVE-2011-4739

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4739?

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 is vulnerable due to the password form field allowing autocomplete. This feature can be exploited by remote attackers, especially in scenarios where workstations are left unattended, facilitating unauthorized access. Specifically, forms located in smb/my-profile and other similar files present avenues for attackers to bypass standard authentication mechanisms and gain access to sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.