PT-2011-5088 · Parallels · Parallels Plesk Small Business Panel

Published

2011-12-16

·

Updated

2017-08-29

·

CVE-2011-4758

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Parallels Plesk Small Business Panel version 10.2.0
Description The issue allows remote attackers to obtain sensitive information by sniffing the network, as it receives cleartext password input over HTTP. This is demonstrated by forms in smb/auth and certain other files.
Recommendations For Parallels Plesk Small Business Panel version 10.2.0, consider restricting access to the smb/auth forms and other affected files until a secure method of password input is implemented, such as using HTTPS to encrypt the data in transit.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4758

Affected Products

Parallels Plesk Small Business Panel