CVE-2011-4737: Infoleak
The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in client@2/domain@1/odbc/dsn@1/properties/.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4737?
CVE-2011-4737 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2011-4737?
To fix CVE-2011-4737, upgrade to a later version of Parallels Plesk Panel that addresses this vulnerability.
What kind of attack does CVE-2011-4737 enable?
CVE-2011-4737 enables attackers to sniff network traffic and potentially capture sensitive passwords sent in HTTP responses.
In which software is CVE-2011-4737 found?
CVE-2011-4737 is found specifically in Parallels Plesk Panel version 10.2.0 build 20110407.20.
What are the impacts of CVE-2011-4737?
The impact of CVE-2011-4737 includes unauthorized access to sensitive information due to inadequate password protection in network communications.