PT-2011-5145 · Parallels · Parallels Plesk Panel

Published

2011-12-16

·

Updated

2017-08-29

·

CVE-2011-4854

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Parallels Plesk Panel version 10.4.4 build20111103.18
Description The issue is related to the Control Panel in Parallels Plesk Panel, where it does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements. This might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving the get enabled product icon program. It is possible that only clients, not the Plesk product, could be affected by this issue.
Recommendations For Parallels Plesk Panel version 10.4.4 build20111103.18, consider restricting access to the get enabled product icon program as a temporary workaround until a patch is available. Additionally, ensure proper configuration of Content-Type HTTP headers to match the corresponding Content-Type data in HTML META elements.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-4854

Affected Products

Parallels Plesk Panel