PT-2011-5091 · Parallels · Parallels Plesk Small Business Panel

Published

2011-12-16

·

Updated

2017-08-29

·

CVE-2011-4761

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Parallels Plesk Small Business Panel version 10.2.0
Description The issue is related to the omission of the Content-Type header's charset parameter for certain resources, which could allow remote attackers to have an unspecified impact. This might be achieved by leveraging an interpretation conflict involving domains/sitebuilder edit.php and certain other files. It is noted that possibly only clients, not the product itself, could be affected by this issue.
Recommendations For Parallels Plesk Small Business Panel version 10.2.0, consider configuring the Content-Type header to include the charset parameter for the affected resources as a temporary workaround. Restrict access to the domains/sitebuilder edit.php file and other involved files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-4761

Affected Products

Parallels Plesk Small Business Panel