CVE-2011-4855: Critical severity plesk vulnerability
The Control Panel in Parallels Plesk Panel 10.4.4build20111103.18 omits the Content-Type header's charset parameter for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving admin/customer-service-plan/list/reset-search/true/ and certain other files. NOTE: it is possible that only clients, not the Plesk product, could be affected by this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4855?
CVE-2011-4855 is considered a moderate severity vulnerability due to its potential impact on the application.
How do I fix CVE-2011-4855?
To fix CVE-2011-4855, it is recommended to upgrade to a later version of Parallels Plesk Panel that has addressed this vulnerability.
What systems are affected by CVE-2011-4855?
CVE-2011-4855 specifically affects Parallels Plesk Panel version 10.4.4_build20111103.18.
Can CVE-2011-4855 lead to remote attacks?
Yes, CVE-2011-4855 may allow remote attackers to exploit an interpretation conflict that can lead to vulnerabilities.
Is CVE-2011-4855 associated with specific web servers?
CVE-2011-4855 is associated with the Parallels Plesk Panel running on Windows Server platforms.