CVE-2011-4767: Infoleak
The Site Editor (aka SiteBuilder) feature in Parallels Plesk Small Business Panel 10.2.0 has web pages containing e-mail addresses that are not intended for correspondence about the local application deployment, which allows remote attackers to obtain potentially sensitive information by reading a page, as demonstrated by js/Wizard/Status.js and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4767?
CVE-2011-4767 has a low severity rating as it exposes potentially sensitive information without direct compromise.
How do I fix CVE-2011-4767?
To fix CVE-2011-4767, ensure that sensitive information is not displayed in the Site Editor feature of Parallels Plesk Small Business Panel.
What versions are affected by CVE-2011-4767?
CVE-2011-4767 specifically affects Parallels Plesk Small Business Panel version 10.2.0.
What impact does CVE-2011-4767 have on users?
The impact of CVE-2011-4767 allows remote attackers to read displayed email addresses which may contain sensitive information.
Is there a patch available for CVE-2011-4767?
As of now, there are no specific patches for CVE-2011-4767; proper configuration adjustments should be made.