First published: Fri Dec 16 2011(Updated: )
Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Plesk | =10.4.4_build20111103.18 | |
Microsoft Windows Server 2003 | ||
Microsoft Windows Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4777 is classified as a cross-site scripting (XSS) vulnerability, which can lead to significant security risks if exploited.
To fix CVE-2011-4777, upgrade the Parallels Plesk Panel to a version that addresses this XSS vulnerability.
CVE-2011-4777 specifically affects Parallels Plesk Panel 10.4.4_build20111103.18.
Attackers can exploit CVE-2011-4777 to inject arbitrary web scripts or HTML into the affected application.
CVE-2011-4777 is primarily related to the Parallels Plesk Panel and does not directly affect operating systems like Windows Server 2003 or 2008.