CVE-2011-4757: Critical severity plesk vulnerability
Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/auth and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4757?
CVE-2011-4757 is considered to have a high severity due to its potential for unauthorized access via unattended workstations.
How do I fix CVE-2011-4757?
To mitigate CVE-2011-4757, disable the autocomplete feature in password form fields within the Parallels Plesk Small Business Panel.
Who is affected by CVE-2011-4757?
CVE-2011-4757 specifically affects users of Parallels Plesk Small Business Panel version 10.2.0.
What are the implications of CVE-2011-4757?
The implications of CVE-2011-4757 include the risk of attackers bypassing authentication mechanisms by exploiting autocomplete functionality.
When was CVE-2011-4757 disclosed?
CVE-2011-4757 was disclosed in 2011, focusing on security vulnerabilities related to password handling.