// For flags

CVE-2011-4755

 

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.

Parallels Plesk Small Business Panel 10.2.0 no valida apropiadamente datos de cadena de texto que son utilizados para almacenamiento en un documento XML, lo que facilita a atacantes remotos provocar una denegación de servicio (error de "parseo") o posiblemente tener otros impactos sin especificar a través de una cookie modificada, como se ha demostrado con cookies de "client@1/domain@1/hosting/file-manager/" y otros archivos determinados.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2011-12-11 CVE Reserved
  • 2011-12-16 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Parallels
Search vendor "Parallels"
Parallels Plesk Small Business Panel
Search vendor "Parallels" for product "Parallels Plesk Small Business Panel"
10.2.0
Search vendor "Parallels" for product "Parallels Plesk Small Business Panel" and version "10.2.0"
-
Affected