CVE-2011-4728: Infoleak
The Server Administration Panel in Parallels Plesk Panel 10.2.0build1011110331.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demonstrated by cookies used by loginup.php3 and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4728?
CVE-2011-4728 is classified as a medium severity vulnerability due to the potential for cookie interception in HTTPS sessions.
How do I fix CVE-2011-4728?
To address CVE-2011-4728, ensure that the secure flag is set for cookies in your server configuration.
Which versions of Parallels Plesk Panel are affected by CVE-2011-4728?
CVE-2011-4728 specifically affects Parallels Plesk Panel version 10.2.0_build1011110331.18.
Can CVE-2011-4728 be exploited remotely?
Yes, CVE-2011-4728 can be exploited remotely by attackers who intercept cookie transmissions.
What type of attack does CVE-2011-4728 enable?
CVE-2011-4728 enables session hijacking by allowing attackers to capture unprotected cookies.