Cross-Site Scripting Vulnerability in Parallels Plesk Small Business Panel 10.2.0
CVE-2011-4765

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4765?

The Site Editor feature in Parallels Plesk Small Business Panel 10.2.0 lacks the HTTPOnly flag in its Set-Cookie headers, which exposes cookies to potential theft through script access. This vulnerability allows remote attackers to exploit sensitive information contained in cookies, as evidenced by vulnerabilities in files associated with the Image Gallery feature and other components.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.