CVE-2011-4768
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving Wizard/Edit/Modules/Image and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
La característica "Site Editor" (SiteBuilder) de Parallels Plesk Small Business Panel 10.2.0 omite el parámetro charset de la cabecera Content-Type para determinados recursos, lo que permite a atacantes remotos tener un impacto sin especificar utilizando un conflicto de interpretación que involucre Wizard/Edit/Modules/Image y otros archivos determinados. NOTA: es posible que sólo clientes, no el producto Plesk, esten afectados por esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-12-11 CVE Reserved
- 2011-12-16 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
http://xss.cx/examples/plesk-reports/plesk-10.2.0-site-editor.html | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Parallels Search vendor "Parallels" | Parallels Plesk Small Business Panel Search vendor "Parallels" for product "Parallels Plesk Small Business Panel" | 10.2.0 Search vendor "Parallels" for product "Parallels Plesk Small Business Panel" and version "10.2.0" | - |
Affected
|