CVE-2011-4766: Infoleak
DISPUTED The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 allows remote attackers to obtain ASP source code via a direct request to wysiwyg/fckconfig.js. NOTE: CVE disputes this issue because ASP is only used in a JavaScript comment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4766?
CVE-2011-4766 is categorized with a disputed severity due to the nature of the vulnerability.
How do I fix CVE-2011-4766?
To mitigate CVE-2011-4766, consider upgrading to a newer version of Parallels Plesk Small Business Panel that addresses this issue.
What are the consequences of CVE-2011-4766?
The vulnerability could allow remote attackers to obtain certain source code, potentially exposing sensitive information.
Is CVE-2011-4766 still exploitable in current systems?
CVE-2011-4766 is less likely to be exploitable in updated systems where the feature has been properly patched.
Which versions of software are affected by CVE-2011-4766?
CVE-2011-4766 specifically affects Parallels Plesk Small Business Panel version 10.2.0.