CVE-2011-4764: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Wizard/Edit/Modules/Image and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4764?
CVE-2011-4764 is classified as a high severity vulnerability due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2011-4764?
To mitigate CVE-2011-4764, updating the Parallels Plesk Small Business Panel to a version that addresses these XSS vulnerabilities is recommended.
What types of attacks can exploit CVE-2011-4764?
CVE-2011-4764 can be exploited to perform cross-site scripting attacks, allowing the injection of arbitrary web scripts.
Which versions of Parallels Plesk Small Business Panel are affected by CVE-2011-4764?
CVE-2011-4764 specifically affects the Parallels Plesk Small Business Panel version 10.2.0.
Where can I find more information about CVE-2011-4764?
Detailed information on CVE-2011-4764 can be found in various security reports and advisories relevant to the vulnerability.