Remote Code Exposure in Parallels Plesk Small Business Panel
CVE-2011-4766

Currently unrated

Key Information:

Vendor

Parallels

Vendor
CVE Published:
16 December 2011

What is CVE-2011-4766?

The Site Editor feature within Parallels Plesk Small Business Panel 10.2.0 presents a security risk, allowing remote attackers to access ASP source code by making a direct request to the file wysiwyg/fckconfig.js. Although the ASP source code is referenced in a JavaScript comment, the potential for unauthorized access raises concerns regarding the security configuration of the platform.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.