CVE-2011-4847: SQL Injection
Published Dec 16, 2011
·Updated
SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.
Affected Software
3 affected components
Parallels Parallels Plesk Panel=10.4.4_build20111103.18
Microsoft Windows 2003 Server
Microsoft Windows Server 2008
Event History
Dec 16, 2011
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Data Sourced
11:55 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4847?
CVE-2011-4847 is considered a critical vulnerability due to its potential for remote SQL injection attacks.
2
How do I fix CVE-2011-4847?
To fix CVE-2011-4847, upgrade to a patched version of Parallels Plesk Panel that addresses this SQL injection vulnerability.
3
What systems are affected by CVE-2011-4847?
CVE-2011-4847 specifically affects Parallels Plesk Panel version 10.4.4_build20111103.18.
4
Can CVE-2011-4847 lead to data loss?
Yes, CVE-2011-4847 can lead to data loss as attackers could execute arbitrary SQL commands.
5
Is CVE-2011-4847 a common vulnerability?
CVE-2011-4847 is recognized as a notable vulnerability within the Parallels Plesk Panel ecosystem.