First published: Fri Dec 16 2011(Updated: )
Parallels Plesk Small Business Panel 10.2.0 does not properly validate string data that is intended for storage in an XML document, which allows remote attackers to cause a denial of service (parsing error) or possibly have unspecified other impact via a crafted cookie, as demonstrated by cookies to client@1/domain@1/hosting/file-manager/ and certain other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Parallels Parallels Plesk Small Business Panel | =10.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4755 is classified as a denial of service vulnerability due to improper validation of string data.
To fix CVE-2011-4755, it is recommended to update Parallels Plesk Small Business Panel to the latest version that addresses this vulnerability.
CVE-2011-4755 specifically affects Parallels Plesk Small Business Panel version 10.2.0.
An attacker can cause a denial of service or potentially exploit the vulnerability further through crafted cookies.
There are known demonstrations of exploits for CVE-2011-4755 that illustrate how crafted cookies can lead to parsing errors.