Page 4 of 17 results (0.001 seconds)

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

Parallels Plesk Small Business Panel 10.2.0 generates web pages containing external links in response to GET requests with query strings for client@1/domain@1/hosting/file-manager/ and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue. Parallels Plesk Small Business Panel 10.2.0 genera páginas web que contienen enlaces externos en respuesta a peticiones GET con peticiones de búsqueda de "client@1/domain@1/hosting/file-manager/" y otros archivos determinados, lo que facilita a atacantes remotos obtener información confidencial leyendo (1) los logs de acceso o (2) Referer del servidor web, relacionado con una filtración de Referer entre dominios. • http://xss.cx/examples/plesk-reports/plesk-10.2.0.html https://exchange.xforce.ibmcloud.com/vulnerabilities/72211 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving domains/sitebuilder_edit.php and certain other files. NOTE: it is possible that only clients, not the SmarterStats product, could be affected by this issue. Parallels Plesk Small Business Panel 10.2.0 omite el parámetro charset de cabeceras Content-Type para determinados recursos, lo que podría permitir a atacantes remotos tener un impacto sin especificar utilizando un conflicto de interpretación que involucre "domains/sitebuilder_edit.php" y otros archivos concretos. NOTA: es posible que sólo clientes, no el producto SmarterStats, podrían estar afectados por este problema. • http://xss.cx/examples/plesk-reports/plesk-10.2.0.html https://exchange.xforce.ibmcloud.com/vulnerabilities/72213 •