First published: Fri Dec 16 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by admin/health/ and certain other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk | =10.2.0_build1011110331.18 | |
Microsoft Windows | ||
Red Hat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4726 describes multiple cross-site scripting (XSS) vulnerabilities in the Server Administration Panel of Parallels Plesk Panel, allowing remote attacks via crafted input.
CVE-2011-4726 affects Parallels Plesk Panel version 10.2.0_build1011110331.18.
To mitigate CVE-2011-4726, ensure to validate and sanitize user inputs to prevent XSS attacks.
CVE-2011-4726 can allow remote attackers to inject arbitrary web scripts or HTML, compromising the integrity and confidentiality of the application.
Users should check with Parallels for any available updates or patches that address CVE-2011-4726.