Cross-Site Scripting Vulnerabilities in Parallels Plesk Small Business Panel
CVE-2011-4764

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4764?

The Site Editor feature in Parallels Plesk Small Business Panel version 10.2.0 is susceptible to multiple cross-site scripting vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web scripts or HTML via specially crafted input into PHP scripts. This flaw can have serious implications as it may lead to unauthorized access or manipulation of the web server's functionality. Affected components include Wizard/Edit/Modules/Image and other files, which could be exploited to compromise the integrity of web applications hosted on the server.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.