CVE-2011-4748: Infoleak
The billing system for Parallels Plesk Panel 10.3.1build1013110726.09 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by js/ajax/core/ajax.inc.js and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4748?
CVE-2011-4748 has a CVSS score indicating moderate severity due to its ability to expose potentially sensitive information.
How do I fix CVE-2011-4748?
To fix CVE-2011-4748, it is recommended to upgrade to a newer version of Parallels Plesk Panel that addresses this vulnerability.
What types of information are at risk with CVE-2011-4748?
CVE-2011-4748 potentially exposes email addresses from web pages intended for internal use, which can lead to sensitive data leakage.
Which versions of Parallels Plesk Panel are affected by CVE-2011-4748?
CVE-2011-4748 affects Parallels Plesk Panel version 10.3.1_build1013110726.09.
Can I use Red Hat Enterprise Linux 6.0 with CVE-2011-4748?
Red Hat Enterprise Linux 6.0 is not vulnerable itself, but it can host affected versions of Parallels Plesk Panel, which may expose vulnerabilities.