SQL Injection Vulnerability in Parallels Plesk Small Business Panel
CVE-2011-4763

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4763?

The Site Editor feature in Parallels Plesk Small Business Panel version 10.2.0 contains multiple SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. These vulnerabilities are triggered through crafted input to specific PHP scripts, including those located in Wizard/Edit/Html. Successful exploitation of these vulnerabilities can lead to unauthorized access to sensitive data and manipulation of the database.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.