CVE-2011-4740
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which makes it easier for remote attackers to obtain sensitive information by reading (1) web-server access logs or (2) web-server Referer logs, related to a "cross-domain Referer leakage" issue.
El panel de control de Parallels Plesk Panel 10.2.0 build 20110407.20 genera páginas web que contienen enlaces externos en respuesta a peticiones GET con cadenas de búsqueda de smb/app/search-data/catalogId/marketplace y otros archivos determinados, lo que facilita a atacantes remotos obtener información confidencial leyendo (1) logs de acceso o (2) de Referer del servidor web. Relacionado con una filtración de Referer entre dominios.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-11 CVE Reserved
- 2011-12-16 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Parallels Search vendor "Parallels" | Parallels Plesk Panel Search vendor "Parallels" for product "Parallels Plesk Panel" | 10.2.0_build20110407.20 Search vendor "Parallels" for product "Parallels Plesk Panel" and version "10.2.0_build20110407.20" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | * | - |
Safe
|
Parallels Search vendor "Parallels" | Parallels Plesk Panel Search vendor "Parallels" for product "Parallels Plesk Panel" | 10.2.0_build20110407.20 Search vendor "Parallels" for product "Parallels Plesk Panel" and version "10.2.0_build20110407.20" | - |
Affected
| in | Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 6.0 Search vendor "Redhat" for product "Enterprise Linux" and version "6.0" | - |
Safe
|