First published: Fri Dec 16 2011(Updated: )
Parallels Plesk Small Business Panel 10.2.0 generates a password form field without disabling the autocomplete feature, which makes it easier for remote attackers to bypass authentication by leveraging an unattended workstation, as demonstrated by forms in smb/auth and certain other files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Parallels Parallels Plesk Small Business Panel | =10.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4757 is considered to have a high severity due to its potential for unauthorized access via unattended workstations.
To mitigate CVE-2011-4757, disable the autocomplete feature in password form fields within the Parallels Plesk Small Business Panel.
CVE-2011-4757 specifically affects users of Parallels Plesk Small Business Panel version 10.2.0.
The implications of CVE-2011-4757 include the risk of attackers bypassing authentication mechanisms by exploiting autocomplete functionality.
CVE-2011-4757 was disclosed in 2011, focusing on security vulnerabilities related to password handling.