First published: Fri Dec 16 2011(Updated: )
The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms on certain pages under admin/index.php/default.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Parallels Parallels Plesk Panel | =10.3.1_build1013110726.09 | |
Red Hat Enterprise Linux | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4749 is considered a medium severity vulnerability due to the potential for unauthorized access through credential bypass.
To fix CVE-2011-4749, disable the autocomplete feature on password fields in your billing system forms.
CVE-2011-4749 addresses the lack of autocomplete disablement for password fields in the Parallels Plesk Panel billing system.
CVE-2011-4749 affects Parallels Plesk Panel version 10.3.1_build1013110726.09.
Yes, CVE-2011-4749 can be exploited remotely by attackers leveraging unattended workstations.