PT-2011-5071 · Parallels · Parallels Plesk Panel

Publicado

2011-12-16

·

Atualizado

2019-04-22

·

CVE-2011-4741

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Parallels Plesk Panel version 10.2.0 build 20110407.20
Description The issue allows remote attackers to obtain potentially sensitive information by reading a web page that includes a database connection string within the Control Panel. This is demonstrated by accessing the /client@2/domain@1/hosting/aspdotnet/ endpoint.
Recommendations For Parallels Plesk Panel version 10.2.0 build 20110407.20, consider restricting access to the /client@2/domain@1/hosting/aspdotnet/ endpoint to minimize the risk of exploitation. Additionally, remove or secure the database connection string from the web page to prevent unauthorized access to sensitive information.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4741

Produtos afetados

Parallels Plesk Panel