Remote Code Exposure in Parallels Plesk Small Business Panel
CVE-2011-4766
Currently unrated
What is CVE-2011-4766?
The Site Editor feature within Parallels Plesk Small Business Panel 10.2.0 presents a security risk, allowing remote attackers to access ASP source code by making a direct request to the file wysiwyg/fckconfig.js. Although the ASP source code is referenced in a JavaScript comment, the potential for unauthorized access raises concerns regarding the security configuration of the platform.
References
Timeline
Vulnerability Reserved
Vulnerability published