CVE-2011-4850: Infoleak
The Control Panel in Parallels Plesk Panel 10.4.4build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, as demonstrated by cookies used by help.php and certain other files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4850?
CVE-2011-4850 has a medium severity rating due to its potential for exposing sensitive information through scripts.
How do I fix CVE-2011-4850?
To fix CVE-2011-4850, ensure the HTTPOnly flag is included in the Set-Cookie headers for all relevant cookies.
What software is affected by CVE-2011-4850?
CVE-2011-4850 affects Parallels Plesk Panel version 10.4.4_build20111103.18.
What type of attack does CVE-2011-4850 facilitate?
CVE-2011-4850 facilitates cross-site scripting (XSS) attacks by allowing scripts to access sensitive cookies.
Is CVE-2011-4850 present in newer versions of Parallels Plesk Panel?
CVE-2011-4850 is specific to version 10.4.4_build20111103.18 and may not be present in later versions.