Cross-Domain Referer Leakage in Parallels Plesk Small Business Panel
CVE-2011-4759

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4759?

The Parallels Plesk Small Business Panel 10.2.0 contains a vulnerability that exposes sensitive information through cross-domain referer leakage. When a GET request is made with specific query parameters, the web application generates responses that include external links. This behavior can lead to attackers obtaining sensitive data by analyzing web-server access logs or referer logs. By exploiting this issue, remote attackers may gain unauthorized access to user information, potentially compromising the security of the affected systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.