CVE-2011-4727: Input Validation
The Server Administration Panel in Parallels Plesk Panel 10.2.0build1011110331.18 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted REST URL parameter, as demonstrated by parameters to admin/ and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4727?
CVE-2011-4727 has a high severity rating due to its potential to cause denial of service and other unspecified impacts.
How do I fix CVE-2011-4727?
To mitigate CVE-2011-4727, upgrade Parallels Plesk Panel to a version that addresses this vulnerability.
What exploitation methods are associated with CVE-2011-4727?
CVE-2011-4727 can be exploited through improper validation of string data in an XML document leading to parsing errors.
Which versions of Parallels Plesk Panel are affected by CVE-2011-4727?
CVE-2011-4727 specifically affects Parallels Plesk Panel version 10.2.0_build1011110331.18.
Can CVE-2011-4727 lead to data exposure?
While primarily leading to denial of service, CVE-2011-4727 could also potentially result in other unspecified impacts, including data exposure.